- ISO/IEC 27001:2022 requires maintained criteria and repeatable assessment results rather than a prescribed matrix.
"Information security management systems — Requirements"
Define two linked sets of criteria before assessing risks: assessment criteria explain how to rate consequence, likelihood, and level; acceptance criteria explain which results can be accepted, by whom, and under what conditions.
ISO/IEC 27005:2022 provides guidance for the ISO/IEC 27001:2022 risk requirements. It does not prescribe a universal matrix, scoring formula, threshold, or approval form.
Structured answer sets in this page tree.
Cited legal and guidance references.
Set risk criteria before evaluating individual risks. Start with the ISMS scope, objectives, interested-party requirements, and risk appetite. Define consequence, likelihood, and level scales; define acceptance thresholds, conditions, and delegated authority; test the method on representative scenarios; then approve, version, publish, and review it. are the decision rules for whether a specific assessed risk may be retained, needs treatment, or requires higher authority. Use a generic matrix only when its scales and thresholds fit the organization's context.
ISO/IEC 27001:2022 clause 6.1.2 requires the organization to establish and maintain both and criteria for performing information security risk assessments. ISO/IEC 27005:2022 explains that assessment criteria determine consequence, likelihood, and level, while acceptance criteria support decisions about whether risk is acceptable or needs further treatment.
These are international standards, not legislation. ISO/IEC 27001 states ISMS requirements and can be used for certification; ISO/IEC 27005 is supporting guidance. A law, regulator, contract, customer requirement, or internal policy can still make particular criteria or approval limits binding for the organization, so record that controlling source separately.
Keep the criteria with the method that applies them. Record scope, objectives, source requirements, scale definitions, time horizon, data and evidence rules, treatment and acceptance thresholds, delegated authority, conditional-acceptance rules, calibration cases, approval, version, effective date, review owner, and change history.
The published method should let an assessor reproduce the branch for a specific risk: determine consequence and likelihood from evidence, calculate or assign the level under the stated rule, test separate overrides and cumulative effects, compare the result with the acceptance criteria, and route the result to the named authority.
Assign the criteria owner, retain calibration and approval evidence, control versions, and set the next review trigger.
Gather the internal and external context first, including objectives, interested parties, applicable laws, regulations, contracts, policies, supplier relationships, technology, operations, and financial constraints. Draft the consequence, likelihood, level, and acceptance rules, then calibrate them with people who own the affected business and technical risks.
Use test cases that expose boundary conditions. For example, a frequently recurring low-consequence event may need evaluation as a cumulative exposure, while a risk involving legal non-compliance may require a separate rule even when its combined matrix score is below the ordinary treatment threshold. ISO/IEC 27005 also allows temporary retention above a normal threshold when authorized criteria permit it, the organization commits to treatment, and the permitted period is defined.
Do not copy a generic matrix without testing it against the organization's objectives and risk classes. Avoid labels such as "unlikely" or "major" without definitions, arithmetic that hides extreme consequences, and a single threshold that ignores duration, cumulative loss, legal or contractual constraints, or decision authority.
Review on the planned governance cycle and after changes to the ISMS scope, objectives, risk appetite, laws, regulations, contracts, suppliers, technology, operations, or threat environment. ISO/IEC 27005 sets no universal annual deadline; the organization chooses intervals appropriate to its ISMS and performs additional assessment when significant changes are proposed or occur. Recalibrate after material incidents, recurring near misses, repeated assessor disagreement, or evidence that ratings no longer match observed outcomes.
"Information security management systems — Requirements"
"Guidance on managing information security risks"