ISO 27001 Risk Assessment: Methodology and Template
An ISO 27001 risk assessment is the systematic process of identifying, analysing, and evaluating information security risks to your organisation. It is the engine that drives your entire ISMS – without a robust risk assessment, you cannot select the right controls, justify exclusions, or pass certification audits. This guide covers the full methodology, step-by-step process, and includes a practical risk register template.
What Is an ISO 27001 Risk Assessment?
A risk assessment under ISO 27001 identifies threats to your information assets, evaluates the likelihood and impact of those threats, and prioritises risks for treatment. The output feeds directly into your risk treatment plan and Statement of Applicability.
The standard does not prescribe a specific methodology. This flexibility allows organisations to choose an approach that matches their size, complexity, and industry. However, the methodology must be defensible, repeatable, and documented.
ISO 27001 Requirements for Risk Assessment (Clause 6.1)
Clause 6.1 of ISO 27001 sets out specific requirements for risk assessment. Your process must:
- Establish and maintain information security risk criteria
- Ensure that repeated risk assessments produce consistent, valid, and comparable results
- Identify risks associated with the confidentiality, integrity, and availability of information
- Analyse the consequences and likelihood of identified risks
- Evaluate risks against predefined acceptance criteria
- Retain documented information about the risk assessment process
Risk Assessment Methodology: Qualitative vs Quantitative
There are two broad approaches to risk assessment methodology. Many organisations use a hybrid model.
| Aspect | Qualitative | Quantitative |
|---|---|---|
| Approach | Descriptive scales (High, Medium, Low) | Numerical values (monetary loss, percentages) |
| Ease of use | Easy to implement and understand | Complex, requires data and expertise |
| Objectivity | Subjective, depends on assessor judgment | Objective, data-driven |
| Best for | SMEs, first-time certifications, broad assessments | Large enterprises, regulated industries, financial quantification |
| Output | Risk matrix (e.g. 5×5 colour-coded grid) | Annual Loss Expectancy (ALE), Return on Security Investment (ROSI) |
| Common tools | Spreadsheets, risk registers, workshop sessions | FAIR model, Monte Carlo simulation, specialised software |
Step 1: Risk Identification
Identify threats, vulnerabilities, and assets that could be affected. Common sources of threats include:
- Cyber threats: malware, phishing, ransomware, denial of service
- Physical threats: fire, flood, power failure, theft
- Human threats: insider threats, human error, social engineering
- Technical threats: system failures, software bugs, network outages
- Legal and regulatory: compliance breaches, contractual penalties
Create an asset inventory and identify which assets are in scope for your ISMS. For each asset, list the threats and existing controls.
Step 2: Risk Analysis
Analyse each risk by assessing its potential consequences and likelihood. You can assign numerical scores or use descriptive scales. A common approach is the 5×5 risk matrix:
| Likelihood / Impact | Insignificant (1) | Minor (2) | Moderate (3) | Major (4) | Catastrophic (5) |
|---|---|---|---|---|---|
| Almost certain (5) | 5 | 10 | 15 | 20 | 25 |
| Likely (4) | 4 | 8 | 12 | 16 | 20 |
| Possible (3) | 3 | 6 | 9 | 12 | 15 |
| Unlikely (2) | 2 | 4 | 6 | 8 | 10 |
| Rare (1) | 1 | 2 | 3 | 4 | 5 |
Step 3: Risk Evaluation
Compare the risk level against your organisation’s risk acceptance criteria. Risks above the threshold require treatment. Define your thresholds clearly in your risk management policy:
- Low risk (1–5): Acceptable; monitor periodically
- Medium risk (6–12): Requires treatment within a defined timeframe
- High risk (13–25): Immediate treatment required; may need escalation to management
Risk Treatment Options
Once risks are evaluated, you must decide how to treat them. The four options are:
| Option | Description | Example |
|---|---|---|
| Risk mitigation | Implement controls to reduce likelihood or impact | Deploying multi-factor authentication to reduce unauthorised access risk |
| Risk acceptance | Knowingly accept the risk without further action | Accepting low-risk, low-impact events that are cheaper to tolerate than fix |
| Risk transfer | Shift the risk to a third party | Purchasing cyber insurance or outsourcing to a managed security provider |
| Risk avoidance | Eliminate the activity that generates the risk | Discontinuing a legacy system that cannot be secured |
Risk Register Template
A risk register is the key output of your risk assessment. Below is a template structure you can adapt for your ISMS:
| Asset | Threat | Vulnerability | Existing Controls | Likelihood | Impact | Risk Level | Treatment | Target Date |
|---|---|---|---|---|---|---|---|---|
| Customer database | SQL injection | Unpatched web application | WAF, network firewall | 3 | 5 | 15 (High) | Apply security patch; implement input validation | Q2 2025 |
| Email system | Phishing attack | Low user awareness | Spam filter | 4 | 3 | 12 (Medium) | Security awareness training; deploy DMARC | Q1 2025 |
| Office server room | Fire | No fire suppression | Smoke detector | 1 | 5 | 5 (Low) | Accept (insurance covers loss) | N/A |
| Employee laptops | Theft | No disk encryption | None | 2 | 4 | 8 (Medium) | Deploy full-disk encryption (BitLocker) | Q1 2025 |
| Cloud infrastructure | Misconfiguration | No automated compliance checks | Manual review | 3 | 4 | 12 (Medium) | Deploy IaC scanning; implement CI/CD security gates | Q3 2025 |
Common Risks by Industry
The types of risks organisations face vary significantly by sector. The table below highlights prevalent risks across different industries.
| Industry | Common Risks | Typical Controls |
|---|---|---|
| Financial services | Fraud, data breach, regulatory non-compliance, insider trading | Segregation of duties, transaction monitoring, encryption, audit logging |
| Healthcare | Patient data breach, system availability, medical device vulnerabilities | Access control, backup and recovery, network segmentation |
| Technology / SaaS | Cloud misconfiguration, API abuse, supply chain compromise | Vulnerability scanning, penetration testing, secure SDLC |
| Manufacturing | OT/ICS compromise, IP theft, supply chain disruption | Network segmentation, physical security, vendor assessments |
| Retail | Payment card fraud, POS malware, customer data theft | PCI DSS compliance, encryption, access controls |
Frequently Asked Questions
How often should I conduct an ISO 27001 risk assessment?
At least annually, or whenever significant changes occur to your organisation, systems, or threat landscape. Some organisations conduct rolling assessments quarterly for high-risk areas.
What is the difference between risk assessment and risk treatment?
Risk assessment identifies, analyses, and evaluates risks. Risk treatment is the subsequent process of selecting and implementing controls to modify the risk level. Both are required by ISO 27001 clause 6.1.
Can I use a spreadsheet for my risk assessment?
Yes. Many organisations successfully use spreadsheet-based risk registers, especially for initial certification. The key is ensuring the methodology is consistent, repeatable, and well-documented. Specialised tools become useful as the organisation grows.
Do I need to assess risks for every single asset?
Not necessarily. You can group assets into logical categories (e.g. all employee workstations, all cloud databases) and assess risks at the group level. The key is to justify your grouping approach and ensure no critical assets are overlooked.
What are risk acceptance criteria?
These are predefined thresholds that determine whether a risk requires treatment or can be accepted. They should be documented in your risk management policy and approved by top management.
Does the risk assessment need to cover third-party suppliers?
Yes, if suppliers process or access your information assets. Supplier-related risks must be included in your risk assessment scope, and controls such as supplier agreements, audits, and NDAs should be considered.
Start Your ISO 27001 Risk Assessment
A well-executed risk assessment is the foundation of a successful ISMS. Whether you are starting from scratch or refining an existing process, the key is to keep it practical, documented, and aligned with your business context.
Need help building your ISO 27001 risk assessment framework? Contact Bitrixme today or send us a message on WhatsApp to speak with an ISO 27001 specialist.