Home / Learn / ISO 27001 Risk Assessment Explained (With a Worked Example)

ISO 27001 Risk Assessment Explained (With a Worked Example)

By Gaurav Malhotra · 2026-09-03 · 6 min read

Risk assessment is the engine of ISO 27001. Clause 6.1.2 requires you to define a method - including risk criteria and an acceptance level - then identify, analyse and evaluate risks, and retain documented results. The standard does not force a formula; it forces consistency. Here is a method that passes audits and is simple enough to run today.

A simple, auditable 5x5 method

Score each risk as Likelihood (1-5) x Impact (1-5), giving a 1-25 score. Define bands up front, for example: 1-4 Low, 5-9 Medium, 10-16 High, 17-25 Critical. State your acceptance level (for example: accept nothing above Medium without sign-off). Documenting the method before scoring is what makes it auditable.

Worked example

AssetThreat / VulnerabilityLIScoreLevelTreatment
Customer databaseRansomware; unpatched OS, no admin MFA4520CriticalMitigate: EDR, MFA, offline backups
Employee laptopsTheft; no full-disk encryption3412HighMitigate: FDE + MDM remote wipe
SaaS admin consoleCredential phishing; no phishing-resistant MFA3412HighMitigate: FIDO2 keys + awareness training
Marketing siteDefacement; outdated CMS plugins224LowAccept with patch monitoring

The four treatment options

  • Mitigate: apply controls (most common) - e.g., MFA, encryption, EDR.
  • Transfer: shift impact, e.g., cyber insurance or a contractually responsible vendor.
  • Avoid: stop the activity causing the risk.
  • Accept: consciously live with it, with risk-owner sign-off.

From assessment to register to SoA

Every assessed risk becomes a register row: asset, threat, vulnerability, score, existing controls, treatment, owner and target date - you can generate and export this with the Risk Register Generator. The treatments you select then map to Annex A controls in your Statement of Applicability, closing the loop between Clauses 6 and 8. If you are new to the standard, start with the beginner guide first.

Frequently asked questions

How often should an ISO 27001 risk assessment be repeated?

At planned intervals - commonly annually - and whenever a significant change occurs, such as a new system, a major incident, a new vendor or a change in scope.

What is risk acceptance and who signs it?

Risks above your acceptance level must be treated. Any risk deliberately left above it must be signed off by the risk owner, because acceptance is a business decision, not a technical one.

Can you explain this in an interview?

CyberVerse AI asks you this topic out loud and grades your answer like a hiring manager.

Practice with CyberVerse AI →