ISO 31000:2018 — Risk Management Guidelines
An international guideline for integrating risk management principles, a framework and a process into organisational governance and decision-making.
It gives leaders a common, adaptable approach for making uncertainty explicit in strategy, operations, projects and investment decisions.
An organisation defines risk criteria for an automation programme, identifies and analyses operational, security and compliance risks, selects treatments, assigns owners and reviews residual risk at governance meetings.
ISO 31000 provides guidelines rather than certifiable requirements. Applying the vocabulary or maintaining a risk register does not demonstrate effective risk management without leadership, integration and evidence-based review.
The standard describes principles for effective risk management, a leadership and governance framework, and a process covering communication, scope and context, risk assessment, treatment, monitoring, review, recording and reporting. Its guidance can be tailored to an organisation's context.
Cybersecurity, Systems Architecture
ISO — ISO 31000:2018 Risk management — Guidelines — https://www.iso.org/standard/65694.html; ISO Online Browsing Platform — ISO 31000:2018 — https://www.iso.org/obp/ui#!iso:std:65694:en
