Skip to content

Risk

ISO 27001 risk assessment without false precision

A usable method connects business impact, scenarios and decisions. A colourful score alone is not yet risk management.

Back to ISO 27001

9 minute read · Content as of 21.07.2026

The method must enable reproducible decisions

ISO/IEC 27001 does not prescribe a specific risk matrix. The organisation must define criteria, produce consistent results and be able to prioritise risks in a comparable way.

A scenario should connect at least one relevant information asset, a cause or threat, a vulnerability and a possible impact. That keeps the assessment actionable.

Risk acceptance belongs before the first assessment

If acceptance criteria are only defined after scoring, the decision quietly adapts to the result. Therefore define thresholds, approvers and escalation rules before the first pass.

  • Rating scales with understandable anchor examples
  • Accountable risk owner
  • Treatment option and target date
  • Residual risk and formal acceptance
  • Triggers for unscheduled reassessments

The register is a steering instrument

A good risk register shows more than scores. It makes decisions, controls, deadlines, dependencies and the next review visible. That is exactly what the free CSV starter is designed for.

Sources used

Back to ISO 27001