How should teams approach likelihood under ISO/IEC 27005?
Assess the of the identified scenario and its consequence with the organization's established criteria. ISO/IEC 27005 permits qualitative, quantitative, and semiquantitative analysis and does not require one universal probability scale or formula.
For deliberate threats, consider capability, motivation, resources, attractiveness, and the cost or benefit of the attack. For accidental or environmental sources, consider human factors, equipment failure, geography, and natural hazards. In every case, consider known weaknesses, , and evidence of how effectively existing controls operate.
- Anchor labels such as low or high to unambiguous ranges or reference points and a stated time period.
- Use expressed in probabilistic terms when aggregating likelihoods; frequency-based terms can still be used for communication.
- Model dependent events as a sequence; do not multiply or compare them as if each event were independent.
- Example: for denial of service, assess the threat landscape and the server's accessibility and vulnerability. The fact that malicious packets are certain after an attack begins does not establish how likely the attack itself is.
- Treat events outside the predictably manageable range as extreme cases when a more precise estimate would not change the decision.
What does mean in ISO/IEC 27005?
is the chance of something happening. ISO/IEC 27005:2022 allows objective or subjective and qualitative or quantitative estimates, including probability or frequency over a stated period. Assess the defined risk scenario and consequence using the organization's established , existing-control evidence, and an explicit statement of uncertainty.
Does ISO/IEC 27005 require a particular formula or scale?
No. The standard permits qualitative, semiquantitative, and quantitative analysis. The chosen scale should cover the relevant range, use unambiguous categories such as a frequency over a stated period, and support consistent, valid, and comparable results. Only expressed in probabilistic terms can be used when aggregating likelihoods.
How should dependent events affect a estimate?
Identify the dependency before combining estimates. A later event can become inevitable once an earlier event occurs, so assessing both as independent events can distort the result. Start with the independent contributory events, model the conditional sequence, and aggregate only with a method that matches those relationships.
ISO/IEC 27005:2022 defines likelihood broadly, and Clauses 7.3.1 and 7.3.3 explain qualitative, quantitative, and semiquantitative analysis, threat factors, controls, dependencies, and uncertainty.