How should teams approach risk acceptance under ISO/IEC 27005?
Risk evaluation compares analysis results with risk criteria to determine whether a risk is acceptable or tolerable and whether treatment is needed. During treatment, help determine whether the proposed treatment is sufficient or further treatment is required.
Acceptance criteria can use several thresholds, different authority levels, different classes of risk, cost-benefit considerations, and absolute or conditional rules. They can also permit short-term retention above the normal threshold when an authorized decision commits the organization to specified controls within a defined period.
- Consider likelihood and consequence separately where an extreme consequence or very frequent minor event should not be hidden by a combined score.
- Check laws, regulations, contracts, policy, objectives, supplier relationships, financial and technical constraints, and human factors before deciding.
- Do not treat insurance or contractual risk sharing as proof that the remaining risk is acceptable.
- Example: can allow a defined short-term exceedance while specified controls are implemented, but the record should identify the permitted extent, completion date, responsible owner, progress checks, and authority that approved the exception.
- An internal acceptance decision does not waive a legal, regulatory, contractual, or statutory duty and does not transfer an authority that the organization does not have.
What does mean in ISO/IEC 27005?
is an informed decision to take a particular risk. It can occur without treatment or during treatment, including acceptance of after controls are considered. The authorized decision-maker should apply approved criteria, record the evidence and rationale, state any conditions or time limit, and keep the accepted risk under monitoring and review.
Can an organization accept risk above its normal threshold?
ISO/IEC 27005:2022 says risk owners can retain a risk that does not meet normal acceptance criteria when prevailing circumstances are not reflected in those criteria. The owner should explicitly identify the override and justify it, record conditions, and obtain higher-level agreement when the authority model requires it. This internal decision cannot override law, regulation, contract, or another binding duty.
Who should approve ?
The risk owner decides whether is acceptable and approves the treatment plan. The organization should assign acceptance authority by threshold or risk class, so higher management can be required when the risk exceeds the owner's delegation or the decision departs from normal criteria.
When should a decision be reviewed?
Review it on the recorded date or expiry and earlier when context, objectives, evidence, threats, vulnerabilities, controls, incidents, ownership, treatment status, or acceptance criteria changes. Accepted risk remains subject to monitoring and review.
ISO/IEC 27005:2022 definitions and Clause 6.4.2 explain acceptance, multiple thresholds, delegated authority, risk classes, conditional or time-limited acceptance, and influencing factors.