ISO 27001 Risk Assessment Explained (With a Worked Example)
Risk assessment is the engine of ISO 27001. Clause 6.1.2 requires you to define a method - including risk criteria and an acceptance level - then identify, analyse and evaluate risks, and retain documented results. The standard does not force a formula; it forces consistency. Here is a method that passes audits and is simple enough to run today.
A simple, auditable 5x5 method
Score each risk as Likelihood (1-5) x Impact (1-5), giving a 1-25 score. Define bands up front, for example: 1-4 Low, 5-9 Medium, 10-16 High, 17-25 Critical. State your acceptance level (for example: accept nothing above Medium without sign-off). Documenting the method before scoring is what makes it auditable.
Worked example
| Asset | Threat / Vulnerability | L | I | Score | Level | Treatment |
|---|---|---|---|---|---|---|
| Customer database | Ransomware; unpatched OS, no admin MFA | 4 | 5 | 20 | Critical | Mitigate: EDR, MFA, offline backups |
| Employee laptops | Theft; no full-disk encryption | 3 | 4 | 12 | High | Mitigate: FDE + MDM remote wipe |
| SaaS admin console | Credential phishing; no phishing-resistant MFA | 3 | 4 | 12 | High | Mitigate: FIDO2 keys + awareness training |
| Marketing site | Defacement; outdated CMS plugins | 2 | 2 | 4 | Low | Accept with patch monitoring |
The four treatment options
- Mitigate: apply controls (most common) - e.g., MFA, encryption, EDR.
- Transfer: shift impact, e.g., cyber insurance or a contractually responsible vendor.
- Avoid: stop the activity causing the risk.
- Accept: consciously live with it, with risk-owner sign-off.
From assessment to register to SoA
Every assessed risk becomes a register row: asset, threat, vulnerability, score, existing controls, treatment, owner and target date - you can generate and export this with the Risk Register Generator. The treatments you select then map to Annex A controls in your Statement of Applicability, closing the loop between Clauses 6 and 8. If you are new to the standard, start with the beginner guide first.
Free tools for this guide
Continue in this cluster
Frequently asked questions
How often should an ISO 27001 risk assessment be repeated?
At planned intervals - commonly annually - and whenever a significant change occurs, such as a new system, a major incident, a new vendor or a change in scope.
What is risk acceptance and who signs it?
Risks above your acceptance level must be treated. Any risk deliberately left above it must be signed off by the risk owner, because acceptance is a business decision, not a technical one.
Can you explain this in an interview?
CyberVerse AI asks you this topic out loud and grades your answer like a hiring manager.
Practice with CyberVerse AI →