Information security
An ISO 27001 risk assessment that holds up to audit
A generic risk register will not survive an ISO 27001 audit, and the reason is structural. A general risk list starts with risks. An information security risk assessment starts with assets - the information and the systems that hold it - and works outward from there. Assessors know the difference on sight, and a register that skips the asset step is the fastest way to a nonconformity.
The good news is that the method is entirely learnable, and once the shape is right the work becomes mechanical. Here is the shape.
Start from assets, not risks
List the information assets in scope: customer databases, source code, the finance system, employee records, the laptops and cloud services that hold them. For each, rate its confidentiality, integrity and availability - the CIA triad. A public marketing brochure scores low on confidentiality; a payroll database scores high on all three. Those ratings give each asset a value, and the value tells you where to spend your attention. You cannot assess a risk to something you have not first identified as worth protecting.
Describe risk as a threat against a vulnerability
This is the phrasing that reads as competent. A risk is not "the database". A risk is a threat exploiting a vulnerability against a named asset. "An attacker (threat) exploits an unpatched server (vulnerability) to access the customer database (asset)." Written this way, the risk is specific enough to score and specific enough to treat. Vague risks produce vague controls; precise risks produce precise ones.
Score it twice: inherent, then residual
Here is the step that separates a real assessment from a checkbox. You score each risk on a 5x5 grid of likelihood against impact - twice.
- Inherent risk is the score before your controls. How bad would this be with nothing in place?
- Residual risk is the score after your controls have done their work. How bad is it now?
The gap between the two numbers is the visible value of your security programme. A risk that drops from a red 20 inherent to a green 4 residual proves the control is earning its keep. A risk that barely moves tells you the control is weak or absent. Scoring once hides all of this; scoring twice makes the effectiveness of your controls a number a board and an assessor can both read.
Inherent risk shows the size of the problem. Residual risk shows what your controls actually bought you. An auditor wants to see both.
Choose one of four treatment options
For every risk, you make a decision, and there are only four options - often taught as the four Ts.
- Treat - apply or strengthen a control to reduce the risk. The most common choice.
- Tolerate - accept the risk as it stands, with a recorded reason. A legitimate choice for a low residual risk, provided someone owns the acceptance.
- Transfer - shift the risk to a third party, typically through insurance or a contract clause.
- Terminate - stop the activity that creates the risk altogether.
The decision is not the assessor's business to second-guess, but the record of the decision very much is. An accepted risk with no owner and no rationale is a finding waiting to happen.
Map every risk to an Annex A control and the SoA
The final connection is what ties the assessment into the wider management system. Each risk you decide to treat should point to the Annex A control that treats it - access control, cryptography, supplier security, and so on. Those same controls are the ones you have marked as applicable on your Statement of Applicability. So the chain runs: asset, to risk, to treatment decision, to Annex A control, to the SoA, to the policy that implements it. When an auditor picks any risk and asks "so what are you doing about this?", you can walk them along that chain without pausing. That traceability, more than any single score, is what makes a risk assessment hold up.
Run it as a live document, not a launch-day artefact. Re-score when a control changes, when a new asset appears, or after an incident - and the residual column keeps telling you the truth about where you stand.
The ISO 27001 way, built in
Assets with CIA ratings, risks as threat plus vulnerability, scored 5x5 inherent and residual, Annex A mapping and the four treatment options - with a live residual heatmap and top-risk list. A framework to organise your own assessment, not legal advice or certification.