Readings attachment for a good discussion and look at some of the frameworks that are used to manage risk within organizations and enterprises. Attached file provided an introduction and comparison of different frameworks. As with anything, there are going to be strengths and weaknesses to all approaches.
Do you think that ISO 27001 standard would work well in the organization that you currently or previously have worked for? If you are currently using ISO 27001 as an ISMS framework, analyze its effectiveness as you perceive in the organization.
Are there other frameworks mentioned has been discussed in the article that might be more effective?
Has any other research you uncover suggest there are better frameworks to use for addressing risks?