GlossaryISO 27001

Risk assessment

Short answer

A risk assessment is the process of identifying the information security risks an organisation faces, estimating how likely and how damaging each one is, and deciding which ones need treatment. It is the foundation of ISO 27001 and of most security frameworks.

The steps

A risk assessment identifies the assets that matter (information, systems, people, suppliers), the threats and weaknesses that could affect them, and then rates each risk by likelihood and impact. The result is compared against the organisation's risk acceptance criteria to decide which risks need action.

Treatment options

Each risk is then treated in one of four ways: reduce it with controls, accept it, avoid it by stopping the activity, or share it, for example through insurance or a supplier. The chosen controls feed the risk treatment plan and the Statement of Applicability.

Inherent and residual risk

Inherent risk is the level before controls. Residual risk is what remains after them. Management must formally accept residual risk.

How often

ISO 27001 requires risk assessments at planned intervals and whenever significant changes occur. In practice, most companies review their risk register at least once a year. The ENS, NIS2 and DORA also require a documented risk analysis.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub