The steps
A risk assessment identifies the assets that matter (information, systems, people, suppliers), the threats and weaknesses that could affect them, and then rates each risk by likelihood and impact. The result is compared against the organisation's risk acceptance criteria to decide which risks need action.
Treatment options
Each risk is then treated in one of four ways: reduce it with controls, accept it, avoid it by stopping the activity, or share it, for example through insurance or a supplier. The chosen controls feed the risk treatment plan and the Statement of Applicability.
Inherent and residual risk
Inherent risk is the level before controls. Residual risk is what remains after them. Management must formally accept residual risk.
How often
ISO 27001 requires risk assessments at planned intervals and whenever significant changes occur. In practice, most companies review their risk register at least once a year. The ENS, NIS2 and DORA also require a documented risk analysis.




