ISO/IEC 27001:2022

ISO 27001 Risk Assessment Explained

Risk assessment is the core of ISO 27001 implementation. It determines which information security risks matter, which controls are needed, and how the organization should prioritize treatment actions.

This guide explains ISO 27001 risk assessment in practical terms, including risk methodology, information assets, threats, vulnerabilities, risk scoring, Risk Treatment Plan and Statement of Applicability.

12 min read Risk Assessment Guide

Key Takeaways

  • ISO 27001 requires organizations to define and apply an information security risk assessment process.
  • Risk assessment should consider information assets, threats, vulnerabilities, impact and likelihood.
  • The Risk Treatment Plan defines how unacceptable risks will be addressed.
  • The Statement of Applicability explains which Annex A controls are applicable and why.
  • Risk assessment, risk treatment and SoA must be aligned, not treated as separate documents.

In This Article

What is ISO 27001 Risk Assessment? Risk Assessment Methodology Asset-Based Risk Assessment Threats and Vulnerabilities Risk Scoring and Evaluation Risk Treatment Plan Link Between Risk Assessment and SoA Risk Review and Update Common Risk Assessment Mistakes What Auditors Look For FAQ

What is ISO 27001 Risk Assessment?

ISO 27001 risk assessment is the process of identifying information security risks, evaluating their significance, and determining whether they require treatment.

The purpose is to help the organization make risk-based decisions about information security controls. Instead of implementing controls blindly, the organization identifies what could go wrong, how serious the impact could be, and what controls are needed to reduce the risk to an acceptable level.

Identify Risks

Determine what could affect the confidentiality, integrity or availability of information assets.

Evaluate Risks

Assess likelihood and impact to determine risk level and priority.

Treat Risks

Decide whether to reduce, avoid, transfer or accept the risk.

Risk Assessment Methodology

ISO 27001 requires the organization to define and apply an information security risk assessment process. The methodology should be consistent, repeatable and suitable for the organization’s context.

A practical methodology should define:

  • Risk criteria
  • Likelihood scale
  • Impact scale
  • Risk rating calculation
  • Risk acceptance criteria
  • Risk treatment options
  • Roles and responsibilities for risk assessment
  • Frequency of risk review

The methodology does not need to be complex. For many organizations, a simple likelihood × impact matrix is sufficient if it is applied consistently and supports decision-making.

Asset-Based Risk Assessment

Many organizations begin ISO 27001 risk assessment by identifying information assets. This approach is practical because risks are easier to understand when they are linked to actual business information, systems, applications and infrastructure.

Information

Business Records

Customer data, employee records, financial records, contracts, reports and confidential files.

Systems

Applications & Platforms

ERP, HR systems, accounting systems, CRM, cloud storage and collaboration platforms.

Infrastructure

Hardware & Network

Servers, laptops, firewalls, routers, mobile devices, storage media and network equipment.

External

Third-Party Services

Cloud providers, outsourced IT support, software vendors, data processors and managed services.

Threats and Vulnerabilities

A risk normally arises when a threat can exploit a vulnerability and cause impact to an information asset.

Information Asset Threat Vulnerability Possible Impact
Customer database Unauthorized access Weak password controls Data breach and contractual noncompliance
Email system Phishing attack Lack of awareness training Credential compromise and malware infection
Cloud storage Data leakage Misconfigured sharing permissions Confidential information disclosure
File server Ransomware Unpatched operating system Loss of availability and operational disruption
Laptop Theft or loss No encryption enabled Exposure of confidential business information

Download the Free ISO 27001 Starter Pack

Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.

Download Starter Pack

Risk Scoring and Evaluation

Risk scoring helps the organization prioritize which risks require treatment. A simple approach is to rate likelihood and impact, then calculate the risk level.

Score Likelihood Impact
1 Rare Minor impact
2 Unlikely Limited impact
3 Possible Moderate impact
4 Likely Major impact
5 Almost certain Severe impact

Example calculation:

Risk Rating = Likelihood × Impact

For example, if likelihood is 4 and impact is 5, the risk rating is 20. The organization should then compare the result against its risk acceptance criteria.

Risk Treatment Plan

Once risks are evaluated, the organization should determine how each unacceptable risk will be treated. The Risk Treatment Plan converts risk assessment results into action.

Reduce

Implement or improve controls to reduce likelihood or impact.

Avoid

Stop the activity or remove the condition causing the risk.

Transfer

Transfer part of the risk through insurance, outsourcing or contractual controls.

Accept

Accept the residual risk when it is within the organization’s acceptance criteria.

Risk Review and Update

Risk assessment should not be a one-time certification activity. Risks should be reviewed periodically and whenever significant changes occur.

Risk assessment should be reviewed when there are:

  • New systems or applications
  • New cloud services or outsourced providers
  • Significant incidents or near misses
  • Major organizational changes
  • New legal, regulatory or contractual requirements
  • Changes in information assets, processes or technology

Common ISO 27001 Risk Assessment Mistakes

  • Using a generic risk register that does not reflect actual information assets.
  • Scoring risks without defined likelihood and impact criteria.
  • Not linking the risk assessment to the Risk Treatment Plan.
  • Preparing a Statement of Applicability that does not align with risks.
  • Accepting high risks without proper justification or approval.
  • Failing to update risks after system changes or security incidents.
  • Treating Annex A controls as a checklist rather than a risk-based control set.

What Auditors Look For

Is the risk assessment methodology defined and consistently applied?
Are information assets and risk owners clearly identified?
Are likelihood, impact and risk acceptance criteria defined?
Are risk assessment results retained as documented information?
Are treatment actions clearly assigned and tracked?
Does the Statement of Applicability align with risk assessment results?
Are accepted risks approved by appropriate authority?
Are risks reviewed after changes, incidents or new requirements?

Frequently Asked Questions (FAQ)

Yes. ISO/IEC 27001 requires organizations to define and apply an information security risk assessment process and retain the results of risk assessments.

Organizations should assess risks relevant to information assets within the ISMS scope. The level of detail should be proportionate to business importance and information security risk.

Risk assessment identifies and evaluates risks. Risk treatment defines what actions will be taken to reduce, avoid, transfer or accept risks.

The risk assessment helps determine which Annex A controls are needed. The Statement of Applicability documents applicable controls, justification and implementation status.

Need ISO 27001 Risk Assessment Templates?

Access the complete ISO 27001 Document Kit with risk assessment register, risk treatment plan, Statement of Applicability, risk acceptance record, procedures and audit-ready ISMS templates.

View ISO 27001 Document Kit