Risk
ISO 27001 risk assessment without false precision
A usable method connects business impact, scenarios and decisions. A colourful score alone is not yet risk management.
9 minute read · Content as of 21.07.2026
The method must enable reproducible decisions
ISO/IEC 27001 does not prescribe a specific risk matrix. The organisation must define criteria, produce consistent results and be able to prioritise risks in a comparable way.
A scenario should connect at least one relevant information asset, a cause or threat, a vulnerability and a possible impact. That keeps the assessment actionable.
Risk acceptance belongs before the first assessment
If acceptance criteria are only defined after scoring, the decision quietly adapts to the result. Therefore define thresholds, approvers and escalation rules before the first pass.
- Rating scales with understandable anchor examples
- Accountable risk owner
- Treatment option and target date
- Residual risk and formal acceptance
- Triggers for unscheduled reassessments
The register is a steering instrument
A good risk register shows more than scores. It makes decisions, controls, deadlines, dependencies and the next review visible. That is exactly what the free CSV starter is designed for.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISO/IEC 27005:2022 · ISO · 2022
- ISMS practice patterns · KaitoSec