The Risk Assessment has not been effectively implemented.
1) The Risk Assessment Results did not show risk related to all types of information assets in each area withing the scope ISMS; e.g.
- The risk assessment of Server in server room has only risks related to physical security of physical assets. It did not include risks related to other assets; e.g. software, people and information.
- The risk related to each specific type of information was not found.
- The risk related to each specific type of people asset was not found.
- The risk related to TelePro software as the main application to provide services to customers was not found