Skip to content

ISO 27001 risk assessment

Describe specific risk scenarios, assess them with consistent criteria and assign an owner. Connect treatment decisions to evidence and residual-risk acceptance.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

A useful risk assessment explains what could happen, which information or service would be affected and what decision is needed. A list containing “hacking” and “human error” does not yet identify where to intervene. ISO/IEC 27005 provides information security risk guidance supporting an ISMS. The examples below are practical working methods, not a prescribed scoring model.

Describe a scenario, not just a threat

Start with a process inside the agreed scope. Describe the event, the conditions that make it possible and the effect on confidentiality, integrity or availability. Include someone who performs the work. Examine existing controls before recommending another one: an installed feature is not necessarily a control whose operation has been demonstrated.

Agree assessment criteria first

Explain what low likelihood and major impact mean for your organisation. Consider service disruption, information loss, recovery work and consequences for affected people. A three-level or five-level scale can be useful, but is not a universal ISO requirement. Record assumptions so that assessors can discuss differences rather than average incompatible scores. Keep uncertainties visible when reliable evidence is not yet available.

Fictional example: a forgotten administrator account

A fictional support team retains an external administrator account after a contract ends. The scenario is more specific than “unauthorised access”: a former contractor can change customer settings because contract end dates do not trigger account removal. The owner checks active accounts, contains the immediate exposure and improves the handover between procurement, the sponsor and administrators. A later sample of completed contracts checks whether that change actually works.

Separate assessment from treatment

PartUseful record
ScenarioEvent, enabling condition, information and consequence.
AssessmentCriteria, current controls, assumptions and priority.
TreatmentSelected action, owner, deadline and expected effect.
VerificationEvidence of implementation and a check of operation.
Residual riskRemaining exposure and the authorised decision-maker.

A lower score is not evidence of improvement

Change the assessment when there is a reason: an operating control, new information or a change in the service. Preserve the earlier assumption and explain why it changed. Do not mark a risk green merely because a policy was written while implementation remains incomplete. Distinguish planned, implemented and verified work in the treatment plan, and review whether the action created another dependency.

Use the register to support decisions

Bring untreated priorities, exceptions and resource needs to management review. Connect necessary controls to the Statement of Applicability. ISO/IEC 27001 is the normative framework; the register should explain how your organisation makes and follows through on its own risk decisions.

Primary sources for this topic

Frequently asked questions

Does ISO 27001 require a 5×5 risk matrix?
A 5×5 matrix is one possible working method, not a universally prescribed model. Choose criteria your organisation can explain and apply consistently. Record what each level means, how existing controls affect the assessment and when treatment is needed. The scenario, supporting assumptions and resulting decision matter more than a number that merely appears precise.
When can residual risk be accepted?
An authorised risk owner should decide against the agreed acceptance criteria and the exposure that actually remains. Record which controls operate, what is still missing and which assumptions apply. A planned action is not yet evidence of lower risk. Include conditions and a review trigger where relevant, so acceptance does not become a forgotten final status.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)