- ISO/IEC 27001:2022 separates risk assessment requirements in clause 6.1.2 from treatment and residual-risk acceptance in clause 6.1.3.
"Information security management systems — Requirements"
Record the assessment in three stages: identify the risk and owner, analyse consequence and likelihood to determine the level, then compare the result with approved criteria and set the treatment priority.
ISO/IEC 27005:2022 does not prescribe an official template, scoring scale, or event-based versus asset-based method. The chosen method must fit the context and support consistent, valid, and comparable results.
Structured answer sets in this page tree.
Cited legal and guidance references.
This template supplies the record layout; define and approve the assessment method separately. Set the scope, purpose, method, criteria, time horizon, and evidence date first. Then describe the scenario, assign an authorized risk owner, analyse consequence and likelihood using current evidence and existing-control effectiveness, determine the risk level, compare it with every applicable acceptance rule, and record the treatment priority, uncertainty, and next review trigger.
ISO/IEC 27001:2022 clause 6.1.2 requires a defined assessment process that produces consistent, valid, and comparable results. The result record should make each required stage visible: identified risks to confidentiality, integrity, and availability; risk owners; assessed consequences and likelihood; determined levels; comparison with criteria; and treatment priorities. The organization may use event-based, asset-based, or another suitable method; ISO/IEC 27005 does not provide an official form.
Give the record a stable identifier, version, status, and change history. Capture the scenario, affected objectives and information, risk sources and events, assets, threats and vulnerabilities where relevant, dependencies, existing controls, control implementation and effectiveness, risk owner, and interested specialists. State whether the analysis is inherent or current risk and do not mix those states in one unexplained score.
Assign the risk owner, retain consequence and likelihood evidence, record uncertainty, and set the next review trigger.
Confirm that the scope, method, and criteria are approved and current. Identify scenarios broadly enough to find material risks, including sources outside the organization's control, then add detail until the owner can understand the cause, event, affected objective, and consequence. Assign an owner with authority to manage the risk before final evaluation.
Do not treat the template as the method. Avoid one-line labels such as "cyberattack," unsupported numeric scores, missing owners, and assessments that cannot be traced to current evidence. Do not list a threat or vulnerability alone when the decision depends on the causal scenario and consequence.
Perform assessment at planned intervals and when significant changes are proposed or occur. ISO/IEC 27005 sets no universal annual cadence. Review sooner when the scope, objectives, owner, assumptions, assets, threat information, vulnerabilities, controls, effectiveness evidence, event dependencies, consequence, likelihood, or criteria materially changes.
"Information security management systems — Requirements"
"Guidance on managing information security risks"