ISO27001-2022-6.1.2
Evaluation Error: TypeError: Cannot read properties of undefined (reading 'file')
    at eval (eval at <anonymous> (plugin:dataview), <anonymous>:3:24)
    at DataviewInlineApi.eval (plugin:dataview:18885:16)
    at evalInContext (plugin:dataview:18886:7)
    at asyncEvalInContext (plugin:dataview:18896:32)
    at DataviewJSRenderer.render (plugin:dataview:18922:19)
    at DataviewJSRenderer.onload (plugin:dataview:18464:14)
    at DataviewJSRenderer.load (app://obsidian.md/app.js:1:1214378)
    at DataviewApi.executeJs (plugin:dataview:19465:18)
    at DataviewCompiler.eval (plugin:digitalgarden:10760:23)
    at Generator.next (<anonymous>)
Description
The organization shall define and apply an information security risk assessment process that:
a) establishes and maintains information security risk criteria that include:
- 
- the risk acceptance criteria; and
 
- 
- criteria for performing information security risk assessments;
 b) ensures that repeated information security risk assessments produce consistent, valid and comparable results;
 c) identifies the information security risks:
 
- criteria for performing information security risk assessments;
- 
- apply the information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for information within the scope of the information security management system; and
 
- 
- identify the risk owners;
 d) analyses the information security risks:
 
- identify the risk owners;
- 
- assess the potential consequences that would result if the risks identified in 6.1.2 c) 1) were to materialize;
 
- 
- assess the realistic likelihood of the occurrence of the risks identified in 6.1.2 c) 1); and
 
- 
- determine the levels of risk;
 e) evaluates the information security risks:
 
- determine the levels of risk;
- 
- compare the results of risk analysis with the risk criteria established in 6.1.2 a); and
 
- 
- prioritize the analysed risks for risk treatment.
 
The organization shall retain documented information about the information security risk assessment process.