When should likelihood be reviewed?
Review likelihood whenever the scenario, time horizon, risk source, threat environment, exposure, vulnerability, control effectiveness, or likelihood criteria changes. Review can be strategic, operational, scheduled, or triggered by an event.
- Trigger reassessment after a newly discovered vulnerability, unexpected audit or control-test result, changed threat actor, incident, material architecture change, or new frequency data.
- Recalibrate scales when categories no longer match the organization's planning horizon or risk profile.
- Record the changed input, new estimate, uncertainty, and effect on treatment or acceptance.
ISO/IEC 27005:2022 Clauses 7.3.3 and 10.5.2 identify changed scope, context, vulnerabilities, control results, threats, and other risk factors as review inputs.