What does ISO/IEC 27001 require before accepting risk?
Clause 6.1.2 requires the risk-assessment process to establish and maintain . The organization identifies risks associated with loss of confidentiality, integrity, and availability within the ISMS scope, identifies risk owners, analyses consequence and realistic likelihood, determines risk levels, compares the results with its criteria, and prioritizes risks for treatment.
Clause 6.1.3 then requires appropriate treatment options, all necessary controls, comparison with Annex A, a Statement of Applicability, and a treatment plan. The risk owners approve that plan and accept the residual information security risks. The standard does not prescribe one scoring scale, approval form, or universal monetary threshold.
- Apply the approved acceptance criteria consistently; do not invent a different threshold for a difficult exception.
- Identify the in the assessment and obtain that owner's approval of the treatment plan and residual-.
- Keep legal, regulatory, contractual, and interested-party requirements visible: accepting an information security risk does not waive an external obligation.
- Decision sequence: assess against the maintained criteria; select and document treatment; determine necessary controls and the residual result; check external obligations; route the plan and residual risk to the identified owner or defined escalation authority; then record the decision and reassessment triggers.
ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3 establish risk-acceptance criteria, risk-owner identification, risk evaluation, treatment planning, and risk-owner approval and residual-risk acceptance.
ISO/IEC 27002:2022 provides control guidance that may support selected treatment controls; it does not replace the risk decision required by ISO/IEC 27001.