Information Security Risk Assessment Process
In ISO/IEC 27001, the information security risk assessment process is defined mainly in Clause 6.1.2 (Planning) and carried out under Clause 8.2 (Operation). It is the foundation of the ISMS because it determines which controls are needed and why. The organization must define and apply a process th… In ISO/IEC 27001, the information security risk assessment process is defined mainly in Clause 6.1.2 (Planning) and carried out under Clause 8.2 (Operation). It is the foundation of the ISMS because it determines which controls are needed and why. The organization must define and apply a process that does the following. First, it must establish and maintain information security risk criteria, including risk acceptance criteria and criteria for performing assessments. Second, the process must produce consistent, valid and comparable results when repeated, so a documented, repeatable methodology is essential. Third, risks must be identified, meaning risks associated with the loss of confidentiality, integrity and availability of information within the ISMS scope, and a risk owner must be assigned to each risk. Fourth, risks must be analysed by assessing the realistic likelihood and potential consequences if they materialize, and then determining risk levels. Fifth, risks must be evaluated by comparing the results against the established criteria and prioritizing them for treatment. The standard does not prescribe a specific method. Organizations may use asset-based, scenario-based or event-based approaches, often guided by ISO/IEC 27005. Under Clause 8.2, assessments must be performed at planned intervals and whenever significant changes are proposed or occur. Documented information on the process (6.1.2) and on its results (8.2) must be retained. The outputs feed directly into risk treatment (6.1.3), the Statement of Applicability, and the risk treatment plan, which risk owners must approve, including acceptance of residual risks. From a Lead Auditor perspective, auditors verify several things. They check that the methodology is documented and that the criteria are clearly defined. They check that results are reproducible and that risk owners are identified with appropriate authority. They confirm that reassessment is triggered by change, and that there is clear traceability from identified risks to selected controls and SoA justifications. Common nonconformities include outdated assessments, inconsistent scoring, missing risk owners, and controls in the SoA that are not linked to assessed risks.
Information Security Risk Assessment Process (ISO/IEC 27001 Clause 6.1.2): A Complete Guide for Lead Auditors
Introduction
The information security risk assessment process is the core of an Information Security Management System (ISMS) built on ISO/IEC 27001. Nearly every other part of the standard depends on its output. This includes the selection of controls, the Statement of Applicability (SoA), the risk treatment plan, internal audits and management review. For an ISO 27001 Lead Auditor candidate, this topic is among the most heavily examined. You must understand both what the standard requires and how an auditor verifies conformity.
1. Why the Risk Assessment Process Is Important
It is the foundation of a risk-based ISMS. ISO/IEC 27001 does not prescribe a fixed set of controls. Each organization selects controls based on its own risks. Without a sound risk assessment, control selection becomes arbitrary.
It drives the Statement of Applicability. Clause 6.1.3 requires the organization to compare the controls it has determined as necessary with Annex A. It must then justify inclusions and exclusions. These justifications trace back to the risk assessment.
It makes results repeatable and defensible. The standard requires that repeated assessments produce consistent, valid and comparable results. This lets management track risk over time and make informed decisions.
It assigns accountability. Identifying risk owners ensures that a person with the right authority and accountability manages each risk and approves its treatment and any residual risk.
It supports business objectives. Linking risk to the confidentiality, integrity and availability (CIA) of information shows how security protects business value. It also helps meet legal, regulatory and contractual obligations.
It is a major audit focus. Certification bodies treat a missing or deficient risk assessment as a serious weakness. It often leads to a major nonconformity, because the whole ISMS rests on it.
2. What It Is: The Requirements of Clause 6.1.2
ISO/IEC 27001:2022 Clause 6.1.2 states that the organization shall define and apply an information security risk assessment process. The process must meet the requirements below.
a) Establish and maintain information security risk criteria, including:
1. Risk acceptance criteria: the level at which risk can be accepted.
2. Criteria for performing information security risk assessments: for example, likelihood and consequence scales and the risk matrix.
b) Ensure consistent, valid and comparable results. Repeated assessments must produce results that are consistent, valid and comparable.
c) Identify the information security risks:
1. Apply the process to identify risks associated with the loss of confidentiality, integrity and availability of information within the scope of the ISMS.
2. Identify the risk owners.
d) Analyse the information security risks:
1. Assess the potential consequences if the identified risks were to materialize.
2. Assess the realistic likelihood of the identified risks occurring.
3. Determine the levels of risk.
e) Evaluate the information security risks:
1. Compare the results of risk analysis with the risk criteria established in a).
2. Prioritize the analysed risks for risk treatment.
Documented information: The organization shall retain documented information about the risk assessment process.
Related clauses you must connect:
Clause 4.1 and 4.2: internal and external issues and interested party requirements feed into risk identification.
Clause 4.3: the ISMS scope defines the boundary of the assessment.
Clause 6.1.1: general actions to address risks and opportunities.
Clause 6.1.3: risk treatment, which covers selecting options, determining controls, comparing with Annex A, producing the SoA and the treatment plan, and obtaining risk owner approval and acceptance of residual risk.
Clause 8.2: perform risk assessments at planned intervals or when significant changes are proposed or occur, and retain documented information of the results.
Clause 8.3: implement the risk treatment plan and retain documented results.
Clause 9.3: management review considers the results of risk assessment and the status of the risk treatment plan.
Supporting guidance: ISO/IEC 27005 gives detailed guidance on information security risk management. ISO 31000 provides general risk management principles and vocabulary. Neither is certifiable, and neither is mandatory for ISO 27001 certification.
3. How It Works: The Process Step by Step
Step 1: Establish the context and the risk criteria.
The organization defines its scales for likelihood and consequence. These may be qualitative (Low, Medium, High), semi-quantitative (1 to 5 scores) or quantitative (monetary values). It also defines how the level of risk is calculated, often as likelihood multiplied by consequence. Finally, it defines the risk acceptance threshold, for example accepting all risks scored 6 or below. Top management should approve these criteria.
Step 2: Risk identification.
Risks can be identified in two main ways:
Asset-based approach: identify assets (information, software, hardware, people, services, sites), then threats, then vulnerabilities, then consequences.
Event-based or scenario-based approach: identify strategic or high-level risk events and their causes without a detailed asset inventory.
The 2022 version does not mandate an asset-based method. The 2005 version did, but the 2013 and 2022 versions removed that requirement. Whatever method is used, a risk owner must be identified for each risk.
Step 3: Risk analysis.
For each risk, the organization estimates the consequence, such as business, legal, reputational or financial impact on CIA. It then estimates the realistic likelihood, taking existing controls into account. Combining the two gives the level of risk.
Step 4: Risk evaluation.
Each risk level is compared with the acceptance criteria. Risks are then prioritized. Risks above the threshold need treatment. Risks within the threshold may be accepted.
Step 5: Hand-off to risk treatment (Clause 6.1.3).
The organization chooses one of four treatment options:
Modify: reduce the risk by applying controls.
Retain: accept the risk.
Avoid: stop the activity that creates the risk.
Share: transfer part of the risk, for example through insurance or outsourcing.
It then determines the necessary controls from any source and compares them with Annex A. Next, it produces the SoA and the risk treatment plan. Risk owners approve the plan and accept the residual risk.
Step 6: Operation and review (Clause 8.2).
The assessment is repeated at planned intervals and whenever significant changes occur. Examples of significant changes include new systems, mergers, major incidents and new regulations. The results are retained as documented information.
Example:
Asset: customer database.
Threat: ransomware.
Vulnerability: unpatched server.
Consequence: 5 (severe availability loss and regulatory fines).
Likelihood: 4.
Risk level: 20.
Acceptance threshold: 8.
Evaluation: the risk is above the threshold, so it needs treatment.
Treatment: modify the risk with patch management, backups and endpoint protection.
Residual risk: 6, accepted by the risk owner (the CIO).
4. How an Auditor Audits the Risk Assessment Process
A Lead Auditor collects objective evidence to check each requirement.
Documented methodology: Is there a documented method that defines the criteria, the acceptance levels and the scales?
Consistency: Do different assessors or business units apply the same scales? Can results from different years be compared?
Coverage: Does the assessment cover the full ISMS scope, all CIA aspects, and the relevant issues from Clauses 4.1 and 4.2?
Risk owners: Are risk owners named? Do they have the authority to manage the risk? Do they know they are owners?
Traceability: Can you trace a risk through to its treatment, then to the SoA control, then to the implemented control and its effectiveness evidence?
Currency: Has the assessment been updated after significant changes and at the planned intervals (Clause 8.2)?
Approval: Have risk owners formally approved the treatment plan and accepted the residual risks?
Typical nonconformities include:
1. No defined acceptance criteria.
2. Risks scored inconsistently across departments.
3. Risk owners not identified, or identified only as a department rather than a person or role with authority.
4. The assessment was not updated after a major change.
5. The SoA does not match the risk treatment plan.
6. Residual risk was not accepted by the risk owners.
7. No retained documented information of results.
Exam Tips: Answering Questions on Information Security Risk Assessment Process
Tip 1: Memorize the structure of Clause 6.1.2. Remember the sequence: criteria, then consistency, then identify, then analyse, then evaluate. Many questions ask which activity belongs to which stage. For example, comparing results with criteria is evaluation, not analysis.
Tip 2: Know the difference between 'shall' and guidance. ISO 27001 requires a defined process. It does not mandate a specific method, ISO 27005, asset inventories for risk identification, or quantitative scoring. Reject answer options that claim a particular method is mandatory.
Tip 3: Distinguish assessment (6.1.2), treatment (6.1.3) and operation (8.2 and 8.3). Clause 6 is about planning the process. Clause 8 is about performing it at planned intervals or on change and retaining the results. If a question asks about re-assessment after a change, the answer is Clause 8.2.
Tip 4: Remember the role of the risk owner. Risk owners are identified during risk identification. They approve the treatment plan and accept residual risk. Top management sets direction, but the risk owner accepts the residual risk.
Tip 5: Recall the key phrase 'consistent, valid and comparable results'. This phrase often appears in questions about methodology quality. Inconsistent scoring between assessors is a nonconformity against 6.1.2 b).
Tip 6: Connect to CIA. Risks must relate to the loss of confidentiality, integrity and availability within the ISMS scope. An assessment that ignores one of these, or areas within scope, is incomplete.
Tip 7: In scenario questions, think like an auditor. Ask yourself three things: What is the requirement? What is the evidence? Is there a gap? Then grade the gap. A minor nonconformity is an isolated lapse, such as one risk record missing an owner. A major nonconformity is a systemic failure or absence, such as no defined process, no acceptance criteria, or no assessment performed at all.
Tip 8: Choose evidence-based answers. Good audit evidence includes the risk methodology document, the risk register, the SoA, the risk treatment plan, risk owner sign-offs, meeting minutes, and interviews with risk owners. Be careful with answers that rely only on what the auditor was told, without corroboration.
Tip 9: Watch for distractors from older versions. The 2005 version required asset-based identification and 'asset owners'. The 2013 and 2022 versions use 'risk owners' and allow any method. Annex A in 2022 has 93 controls in 4 themes, compared with 114 controls in 14 domains in 2013.
Tip 10: Link outputs to downstream clauses. In essay or long-answer questions, show the chain:
Context (4.1, 4.2 and 4.3), then risk assessment (6.1.2), then treatment and SoA (6.1.3), then implementation (8.2 and 8.3), then monitoring (9.1), then internal audit (9.2), then management review (9.3), then improvement (10).
Showing this chain demonstrates that you understand the system as a whole.
Tip 11: Use precise terminology. Use the terms risk criteria, risk acceptance criteria, likelihood, consequence, level of risk, risk owner, residual risk and documented information. Examiners reward correct vocabulary.
Tip 12: When drafting a nonconformity statement, include three parts:
1. The requirement, for example: ISO/IEC 27001:2022 Clause 6.1.2 a) requires the organization to establish risk acceptance criteria.
2. The evidence, for example: the risk methodology v2.1 does not define acceptance levels, and 45 risks in the register have no evaluation decision.
3. The statement of the gap.
Keep it factual, objective and traceable.
Summary
The information security risk assessment process requires the organization to do the following:
1. Define criteria.
2. Ensure repeatable results.
3. Identify CIA risks and their owners.
4. Analyse consequences and likelihood.
5. Evaluate risks against the criteria and prioritize them.
6. Keep documented evidence.
It is the engine of the ISMS and feeds risk treatment, the SoA and continual improvement. For the exam, remember three things: the five sub-requirements, the separation between Clause 6 (planning) and Clause 8 (operation), and the central role of risk owners. Then approach every scenario with the auditor's mindset: requirement, evidence and conformity.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!