FAQGlobalISO/IEC 27005

ISO/IEC 27005 FAQ Asset and Scenario Modeling

Use an event-based approach to start with risk sources, events, and consequences at a strategic level. Use an asset-based approach to trace supporting assets, threats, vulnerabilities, and operational paths in more detail. ISO/IEC 27005:2022 allows either approach or both.

The standard supplies guidance rather than a mandatory scoring model, legal rule, or standalone certification scheme.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Choose the starting point that fits the decision. Event-based identification is useful for high-level scenarios about how risk sources can affect business objectives. Asset-based identification is useful when teams need detailed paths through assets, threats, and vulnerabilities to select controls. Both approaches can describe the same and can be combined.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams model assets and scenarios under ISO/IEC 27005 risk assessments?

ISO/IEC 27005:2022 recognizes two common starting points. The event-based approach identifies strategic scenarios by considering risk sources, events, interested parties, and consequences. It can reach a useful high-level view without first cataloguing every asset. The asset-based approach inspects primary and supporting assets, threats, and vulnerabilities to build detailed operational scenarios and identify asset-specific treatment.

The approaches differ mainly in where analysis starts. Event-based work often drills down from business exposure to contributing assets; asset-based work often builds up from assets to accumulated business consequences. Use either or both, but describe each scenario as a sequence or combination of events leading from an initial cause to an unwanted consequence.

ISO/IEC 27005 is guidance supporting ISO/IEC 27001. It does not require an event-based or asset-based format, complete inventory of every possible asset-threat-vulnerability combination, named threat-modeling technique, or universal scenario template. Another identification approach is acceptable when it produces consistent, valid, and comparable results.

  • Identify the affected confidentiality, integrity, or availability objective and the business asset or process that carries the consequence.
  • Map primary assets, such as information or business processes, to supporting assets, such as people, systems, networks, sites, and services; a server matters here because of the information or process it supports.
  • Describe the path from initial cause through relevant events and control conditions to the unwanted business consequence; record assumptions and uncertainty where the path is incomplete.
  • Keep hazards or attack paths separate when they need different controls, even if they are combined later for reporting.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clause 7.2.1 and Annex A explain event-based and asset-based identification, their different starting points, and their use together.

Question 2

What evidence should support the asset and scenario modeling decision?

A useful scenario record shows the scope and purpose, affected objectives, initial cause, risk source, events, consequence, relevant assets, threats, vulnerabilities, existing controls, and dependencies. It should also identify the evidence and assumptions used to estimate consequence and likelihood.

For asset-based work, document dependencies between primary and supporting assets so the same propagated risk is not assessed twice. For event-based work, show how the risk source can use the organization's ecosystem or business processes to reach the affected business asset.

For example, flooding, fire, power spikes, and vandalism can all affect one data centre. They may be aggregated for an enterprise exposure view, but ISO/IEC 27005 says they should remain separate for treatment when each hazard needs different controls. Likewise, a personal-data loss can be a specific instance of a broader data-loss scenario when its consequences and controls differ.

  • Use architecture and data-flow records, asset inventories, process maps, supplier information, incident history, threat information, vulnerability findings, and control tests that match the scenario.
  • Record where a path depends on another event; dependent events should not be treated as independent probabilities.
  • State why scenarios were split, combined, or excluded and which control applies to each retained scenario.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clause 7.2.1 and Annex A.2 connect scenarios to assets, events, threats, vulnerabilities, dependencies, consequences, and controls.

Question 3

Who owns and approves asset and scenario modeling decisions?

Assign each identified risk to a risk owner who can understand the business consequence and direct or escalate treatment. Analysts, architects, asset owners, process owners, suppliers, and control specialists can build the scenario, but contributing evidence does not by itself make them the risk owner. The owner must have both accountability and authority and should be assigned during the assessment, not after a treatment decision is already drafted.

  • Name the business or process owner who validates the consequence and the technical owners who validate assets, vulnerabilities, and controls.
  • Assign treatment actions to people who control the affected assets or processes, while keeping risk acceptance with the authorized risk owner.
  • Escalate when one scenario crosses business units or when no single owner has authority over the full exposure.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 7.2.1 and 7.2.2 explain how interviews support scenario development and say identified risks should be associated with accountable, authorized risk owners.

Question 4

When should asset and scenario modeling be reviewed?

Review a scenario when its path, evidence, or consequence can change. Strategic review addresses changes in objectives, business assets, risk sources, interested parties, or the wider ecosystem. Operational review updates assets, threats, vulnerabilities, dependencies, control effectiveness, and treatment. ISO/IEC 27005 sets no universal annual deadline; use planned intervals appropriate to the ISMS and additional review when significant changes are proposed or occur.

  • Trigger review after a system or process redesign, supplier change, new attack path, significant vulnerability, incident, unexpected control test, or asset-owner change.
  • Recheck asset dependencies after migrations, outsourcing, acquisitions, or shared-service changes.
  • Record whether the change creates a new scenario, changes likelihood or consequence, requires different controls, changes the risk owner, or invalidates a previous acceptance decision.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 5.2, 9.1, and 10.5.2 support strategic, operational, planned, and change-driven review of scenarios and treatment.

Primary sources

References and citations

iso.org
Referenced sections
  • Official listing for the ISO/IEC 27001:2022 ISMS requirements that ISO/IEC 27005 risk guidance supports.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 5.2, 9.1, and 10.5.2 support strategic, operational, planned, and change-driven review of scenarios and treatment.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.