Risk assessment is the foundation of the ISO 27001 Information Security Management System. Clause 6.1.2 requires organizations to define and apply an information security risk assessment process that establishes risk criteria, ensures consistent and repeatable results, and identifies risks to the confidentiality, integrity, and availability of information. The risk assessment drives every subsequent ISMS decision, from control selection to resource allocation. This guide covers methodology selection, the assessment process, risk treatment planning, and alignment with ISO 27005.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
ISO 27001 does not prescribe a specific methodology. Common choices include asset-based approaches (aligned with ISO 27005), scenario-based approaches, and factor-based methodologies like NIST SP 800-30 or OCTAVE. Choose based on your organization's size, complexity, and existing practices. The methodology must be documented and produce consistent, repeatable results.
Full risk assessments should be performed at planned intervals, typically annually. Additionally, targeted assessments are required when significant changes occur such as new systems, business process changes, security incidents, or organizational restructuring. The risk assessment is a continuous process, not a one-time activity.
Risk assessment identifies, analyzes, and evaluates risks by determining their likelihood and impact. Risk treatment determines how to address identified risks through modification (controls), avoidance, sharing, or retention. Risk assessment informs treatment decisions; treatment implements the response to assessed risks.
No. ISO 27005 is a guidance standard, not a requirement for ISO 27001 certification. However, it provides detailed risk management guidance that aligns well with ISO 27001 Clause 6.1.2 requirements and many organizations find it valuable for structuring their risk assessment process.
A risk register is the central document that catalogs all identified risks, their assessed likelihood and impact, current risk levels, treatment decisions, control assignments, risk owners, and residual risk levels. It serves as the foundation for risk treatment planning and ongoing risk management.
Risk acceptance criteria define the threshold below which risks are acceptable without further treatment. They should be established by management based on the organization's risk appetite, business objectives, legal requirements, and stakeholder expectations. Criteria are typically expressed as risk levels (e.g., Low and Medium risks are accepted, High and Critical require treatment).
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for ISO 27001 compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free