Practical toolGlobalISO/IEC 27005

ISO/IEC 27005 Risk Assessment Template

Record the assessment in three stages: identify the risk and owner, analyse consequence and likelihood to determine the level, then compare the result with approved criteria and set the treatment priority.

ISO/IEC 27005:2022 does not prescribe an official template, scoring scale, or event-based versus asset-based method. The chosen method must fit the context and support consistent, valid, and comparable results.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This template supplies the record layout; define and approve the assessment method separately. Set the scope, purpose, method, criteria, time horizon, and evidence date first. Then describe the scenario, assign an authorized risk owner, analyse consequence and likelihood using current evidence and existing-control effectiveness, determine the risk level, compare it with every applicable acceptance rule, and record the treatment priority, uncertainty, and next review trigger.

Section 1

What should an ISO/IEC 27005 risk assessment record contain?

ISO/IEC 27001:2022 clause 6.1.2 requires a defined assessment process that produces consistent, valid, and comparable results. The result record should make each required stage visible: identified risks to confidentiality, integrity, and availability; risk owners; assessed consequences and likelihood; determined levels; comparison with criteria; and treatment priorities. The organization may use event-based, asset-based, or another suitable method; ISO/IEC 27005 does not provide an official form.

  • Context: identify the ISMS scope, assessment purpose, business objectives, internal and external issues, interested-party requirements, assumptions, time horizon, method, criteria version, assessor, and assessment and evidence dates.
  • Identification: describe the sequence from cause or event to unwanted consequence. Use an event-based or asset-based approach, or another suitable method, without forcing every risk into the same wording pattern.
  • Ownership: name a risk owner with the accountability, authority, and understanding needed to manage the risk; name business or technical specialists who supplied material evidence.
  • Decision: record the evaluation result and priority. Selecting and implementing controls belongs to treatment; accepting residual risk is a separate owner decision.
Section 2

Which fields make an assessment reviewable?

Give the record a stable identifier, version, status, and change history. Capture the scenario, affected objectives and information, risk sources and events, assets, threats and vulnerabilities where relevant, dependencies, existing controls, control implementation and effectiveness, risk owner, and interested specialists. State whether the analysis is inherent or current risk and do not mix those states in one unexplained score.

  • Consequence: record the selected band or value; affected confidentiality, integrity, or availability objective; concrete harm to people, operations, finances, reputation, duties, or other applicable dimensions; cascading or cumulative effects; time horizon; evidence; and rationale.
  • Likelihood: record the selected band; frequency or probability meaning and period; history or statistics; deliberate-source capability and motivation where relevant; accidental, natural, technical, or human factors; threat and vulnerability evidence; existing-control effect; dependencies between events; uncertainty; and rationale.
  • Result: record the calculation or decision rule, level of risk, separate extreme-consequence or high-likelihood test, class-specific and legal or contractual rule, criteria result, confidence or uncertainty, treatment priority, decision owner, review date, and event-driven triggers.
  • Evidence: reference dated source records rather than pasting unsupported conclusions. Identify evidence owners, gaps, contested assumptions, and the decision impact if an uncertain input changes.
Section 3

How should teams create and approve the assessment record?

Confirm that the scope, method, and criteria are approved and current. Identify scenarios broadly enough to find material risks, including sources outside the organization's control, then add detail until the owner can understand the cause, event, affected objective, and consequence. Assign an owner with authority to manage the risk before final evaluation.

  • Analyse: assess consequence and likelihood against the defined scales, considering existing controls and their actual effectiveness. Use rough estimates when sufficient for the decision, but state the evidence and uncertainty.
  • Evaluate: apply every relevant criterion, consider cumulative effects and confidence in the result, investigate material disagreement between assessors and owners, and prioritize risks that need treatment.
  • Quality review: have relevant business and technical specialists challenge material assumptions, verify the owner and criteria version, and check that another trained assessor could reproduce the result.
  • Handoff: retain the approved assessment and rationale as documented information. Route risks that exceed acceptance criteria to treatment; route acceptable risks to the authorized owner for the applicable acceptance decision and monitoring.
Section 4

Which recordkeeping mistakes should teams avoid?

Do not treat the template as the method. Avoid one-line labels such as "cyberattack," unsupported numeric scores, missing owners, and assessments that cannot be traced to current evidence. Do not list a threat or vulnerability alone when the decision depends on the causal scenario and consequence.

  • Do not assume every event is independent. Record dependencies so likelihood is not double-counted or assessed at the wrong point in the scenario.
  • Do not hide uncertainty in a precise-looking number. State limited data, contested assumptions, scale limitations, and the effect they could have on the decision.
  • Do not use the assessment result as residual-risk acceptance. Treatment planning, implementation, effectiveness assessment, and risk-owner acceptance follow separately.
  • Do not aggregate risks that need different controls merely to produce one corporate score. Keep the treatment-level records separate and aggregate only when the method explains how.
Section 5

When should the assessment record be reviewed?

Perform assessment at planned intervals and when significant changes are proposed or occur. ISO/IEC 27005 sets no universal annual cadence. Review sooner when the scope, objectives, owner, assumptions, assets, threat information, vulnerabilities, controls, effectiveness evidence, event dependencies, consequence, likelihood, or criteria materially changes.

  • Set the next review date to fit the ISMS and the speed at which the scenario can change; ISO/IEC 27005 does not prescribe one universal cadence.
  • Name the evidence owners and triggers that create an out-of-cycle assessment, including incidents, failed tests, new vulnerabilities, significant projects, and changed obligations.
  • Create a new version when the decision changes and preserve the previous assessment, criteria version, and rationale.
  • For a proposed or completed significant change, retain the new assessment. If no additional assessment was performed, document why the change was not significant.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 27001:2022 separates risk assessment requirements in clause 6.1.2 from treatment and residual-risk acceptance in clause 6.1.3.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 clauses 5.2, 9.1, and 10.5 ground planned and event-driven reassessment and monitoring of changing risk factors.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.