Risk assessment is the core of ISO 27001 implementation. It determines which information security risks matter, which controls are needed, and how the organization should prioritize treatment actions.
This guide explains ISO 27001 risk assessment in practical terms, including risk methodology, information assets, threats, vulnerabilities, risk scoring, Risk Treatment Plan and Statement of Applicability.
ISO 27001 risk assessment is the process of identifying information security risks, evaluating their significance, and determining whether they require treatment.
The purpose is to help the organization make risk-based decisions about information security controls. Instead of implementing controls blindly, the organization identifies what could go wrong, how serious the impact could be, and what controls are needed to reduce the risk to an acceptable level.
Determine what could affect the confidentiality, integrity or availability of information assets.
Assess likelihood and impact to determine risk level and priority.
Decide whether to reduce, avoid, transfer or accept the risk.
ISO 27001 requires the organization to define and apply an information security risk assessment process. The methodology should be consistent, repeatable and suitable for the organization’s context.
A practical methodology should define:
The methodology does not need to be complex. For many organizations, a simple likelihood × impact matrix is sufficient if it is applied consistently and supports decision-making.
Many organizations begin ISO 27001 risk assessment by identifying information assets. This approach is practical because risks are easier to understand when they are linked to actual business information, systems, applications and infrastructure.
Customer data, employee records, financial records, contracts, reports and confidential files.
ERP, HR systems, accounting systems, CRM, cloud storage and collaboration platforms.
Servers, laptops, firewalls, routers, mobile devices, storage media and network equipment.
Cloud providers, outsourced IT support, software vendors, data processors and managed services.
A risk normally arises when a threat can exploit a vulnerability and cause impact to an information asset.
| Information Asset | Threat | Vulnerability | Possible Impact |
|---|---|---|---|
| Customer database | Unauthorized access | Weak password controls | Data breach and contractual noncompliance |
| Email system | Phishing attack | Lack of awareness training | Credential compromise and malware infection |
| Cloud storage | Data leakage | Misconfigured sharing permissions | Confidential information disclosure |
| File server | Ransomware | Unpatched operating system | Loss of availability and operational disruption |
| Laptop | Theft or loss | No encryption enabled | Exposure of confidential business information |
Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.
Download Starter PackRisk scoring helps the organization prioritize which risks require treatment. A simple approach is to rate likelihood and impact, then calculate the risk level.
| Score | Likelihood | Impact |
|---|---|---|
| 1 | Rare | Minor impact |
| 2 | Unlikely | Limited impact |
| 3 | Possible | Moderate impact |
| 4 | Likely | Major impact |
| 5 | Almost certain | Severe impact |
Example calculation:
Risk Rating = Likelihood × Impact
For example, if likelihood is 4 and impact is 5, the risk rating is 20. The organization should then compare the result against its risk acceptance criteria.
Once risks are evaluated, the organization should determine how each unacceptable risk will be treated. The Risk Treatment Plan converts risk assessment results into action.
Implement or improve controls to reduce likelihood or impact.
Stop the activity or remove the condition causing the risk.
Transfer part of the risk through insurance, outsourcing or contractual controls.
Accept the residual risk when it is within the organization’s acceptance criteria.
The Statement of Applicability is one of the most important outputs of ISO 27001 planning. It explains which Annex A controls are applicable, whether they are implemented, and why any controls are excluded.
| Risk Assessment Output | SoA Connection |
|---|---|
| Unauthorized access risk | Access control, authentication and privileged access controls may be applicable. |
| Cloud misconfiguration risk | Cloud service security, configuration and supplier controls may be applicable. |
| Ransomware risk | Backup, malware protection, vulnerability management and incident response controls may be applicable. |
| Loss of laptop containing confidential data | Endpoint security, encryption, asset control and incident reporting controls may be applicable. |
A strong ISMS clearly shows the relationship between risks, treatment decisions and the applicable Annex A controls.
Risk assessment should not be a one-time certification activity. Risks should be reviewed periodically and whenever significant changes occur.
Risk assessment should be reviewed when there are:
Yes. ISO/IEC 27001 requires organizations to define and apply an information security risk assessment process and retain the results of risk assessments.
Organizations should assess risks relevant to information assets within the ISMS scope. The level of detail should be proportionate to business importance and information security risk.
Risk assessment identifies and evaluates risks. Risk treatment defines what actions will be taken to reduce, avoid, transfer or accept risks.
The risk assessment helps determine which Annex A controls are needed. The Statement of Applicability documents applicable controls, justification and implementation status.
Access the complete ISO 27001 Document Kit with risk assessment register, risk treatment plan, Statement of Applicability, risk acceptance record, procedures and audit-ready ISMS templates.
View ISO 27001 Document Kit