A useful risk assessment explains what could happen, which information or service would be affected and what decision is needed. A list containing “hacking” and “human error” does not yet identify where to intervene. ISO/IEC 27005 provides information security risk guidance supporting an ISMS. The examples below are practical working methods, not a prescribed scoring model.
Describe a scenario, not just a threat
Start with a process inside the agreed scope. Describe the event, the conditions that make it possible and the effect on confidentiality, integrity or availability. Include someone who performs the work. Examine existing controls before recommending another one: an installed feature is not necessarily a control whose operation has been demonstrated.
Agree assessment criteria first
Explain what low likelihood and major impact mean for your organisation. Consider service disruption, information loss, recovery work and consequences for affected people. A three-level or five-level scale can be useful, but is not a universal ISO requirement. Record assumptions so that assessors can discuss differences rather than average incompatible scores. Keep uncertainties visible when reliable evidence is not yet available.
Fictional example: a forgotten administrator account
A fictional support team retains an external administrator account after a contract ends. The scenario is more specific than “unauthorised access”: a former contractor can change customer settings because contract end dates do not trigger account removal. The owner checks active accounts, contains the immediate exposure and improves the handover between procurement, the sponsor and administrators. A later sample of completed contracts checks whether that change actually works.
Separate assessment from treatment
| Part | Useful record |
|---|---|
| Scenario | Event, enabling condition, information and consequence. |
| Assessment | Criteria, current controls, assumptions and priority. |
| Treatment | Selected action, owner, deadline and expected effect. |
| Verification | Evidence of implementation and a check of operation. |
| Residual risk | Remaining exposure and the authorised decision-maker. |
A lower score is not evidence of improvement
Change the assessment when there is a reason: an operating control, new information or a change in the service. Preserve the earlier assumption and explain why it changed. Do not mark a risk green merely because a policy was written while implementation remains incomplete. Distinguish planned, implemented and verified work in the treatment plan, and review whether the action created another dependency.
Use the register to support decisions
Bring untreated priorities, exceptions and resource needs to management review. Connect necessary controls to the Statement of Applicability. ISO/IEC 27001 is the normative framework; the register should explain how your organisation makes and follows through on its own risk decisions.