How should teams approach impact under ISO/IEC 27005?
ISO/IEC 27005 defines as the outcome of an event affecting objectives. Consequences can be certain or uncertain, direct or indirect, positive or negative, qualitative or quantitative, and can escalate through cascading or cumulative effects. Information security analysis normally focuses on negative effects from a failure to preserve .
Describe what happens to the affected business process or objective if the scenario occurs. Estimate lost time or data, disruption, severity, and recovery cost. Add legal, regulatory, contractual, safety, financial, customer, supplier, or reputational effects only when they are relevant to the defined context and supported by evidence.
- Use defined categories with observable anchors, such as downtime, records affected, financial loss, recovery effort, or safety effect.
- State how multiple types are combined and how the method handles a rare extreme consequence.
- Keep vulnerability severity separate: a technically severe weakness can have limited business in one context and serious consequence in another.
- Example: loss of confidentiality in a personal-data scenario can cause information loss and privacy harm, then create a separate legal or regulatory . Rate the supported consequence chain, not the vulnerability label.
- Example: for a monetary scale, the organization's tolerable annual write-off and a loss that would threaten its survival can anchor the lower and upper ends. Intermediate bands should fit its context; ISO/IEC 27005 does not prescribe universal amounts.
What does impact mean in an ISO/IEC 27005 risk assessment?
ISO/IEC 27005 uses the term for the outcome of an event affecting objectives. On this page, impact means that consequence, not a vulnerability's technical severity. Start with the relevant loss of , trace the direct, indirect, cascading, and cumulative effects on the defined business objectives, then apply the organization's approved .
Does ISO/IEC 27005 prescribe a universal impact scale?
No. ISO/IEC 27005:2022 allows qualitative or quantitative and says the categories should fit the organization's internal and external context. Define the categories and their observable anchors clearly. Where different domains use different units, it is useful to cross-reference them to a common anchoring scale so equivalent consequences can be compared.
Should a CVSS or vulnerability severity score determine impact?
No. A vulnerability score can inform the scenario, but impact depends on the to objectives in the assessed context. The same weakness can have limited consequence in an isolated test service and severe consequence in a safety-critical or regulated production process.
ISO/IEC 27005:2022 definitions and Clause 7.3.2 support consequence analysis against objectives, including confidentiality, integrity, availability, operational loss, severity, and recovery cost.