ISO 27001 Risk Assessment: How to Run One

ISO 27001 risk assessment process explained
ISO 27001 Risk Assessment: How to Run One | Osto

ISO 27001 risk assessment, explained step by step: how to find what could go wrong, score it, and turn it into the control decisions the rest of your ISMS depends on.

Osto Security Team9 min readCompliance & Trust

TL;DR

The risk assessment is the engine of ISO 27001. You identify what could go wrong with the information you hold, score each risk by likelihood and impact, and record it all in a risk register. Those results decide which Annex A controls you implement.

Get it right and everything downstream, the Statement of Applicability, the controls, the audit, follows logically. Skip it or fake it, and the whole ISMS rests on nothing.

ISO 27001 risk assessment: why it is the engine of the whole standard

Almost every other part of ISO 27001 flows from the risk assessment. It decides which controls you need, justifies your Statement of Applicability, and gives the auditor the logic behind your entire security programme. A risk assessment is the process of working out what could go wrong with the information you hold, how likely it is, and how much it would hurt.

Why it matters
Annex A is a menu of 93 controls, but your risk assessment is what tells you which to order. Without it, control selection is guesswork, and auditors can tell the difference immediately.

The five-step process

A sound risk assessment follows a repeatable sequence. You do not need enterprise software to run it, but you do need to run it honestly.

The risk assessment process
Five steps, from assets to the risk register
1Identify assets 2Spot threats 3Score impact 4Prioritise 5Risk register
1

Identify assets

  • What information and systems you hold
  • Customer data, code, infrastructure
2

Identify threats

  • What could compromise each asset
  • Breach, loss, misuse, outage
3

Score likelihood and impact

  • How probable, how damaging
  • A simple scale is fine
4

Prioritise

  • Rank by combined risk score
  • Focus effort where it matters

The risk register

The output of the assessment is a risk register: a living record of each identified risk, its score, its owner, and what you plan to do about it. The register is what you carry into the risk treatment stage and what the auditor will review to see that your process is real and maintained.

Keep it living
A risk register is not a one-time deliverable. New systems, new data, and new threats change the picture, so the register should be revisited on a schedule and whenever something material changes.

From risk to treatment

Identifying risk is only half the job. For each risk you decide how to treat it: reduce it by applying a control, accept it, avoid it by stopping the activity, or transfer it, for example through insurance. Those decisions become your risk treatment plan, which in turn drives your Statement of Applicability.

Mistakes to avoid

  • Using a generic template unchanged. A risk assessment that does not reflect your actual business convinces no one.
  • Over-engineering the scoring. A clear, simple scale beats an elaborate model nobody maintains.
  • Assessing once and forgetting. A stale register fails at the surveillance audit.
  • Skipping asset identification. You cannot assess risk to assets you have not listed.

The lean-team path to a real risk assessment

The assessment itself is analytical work, but treating the risks depends on controls that actually run, and evaluating them depends on visibility into your systems. When your security is scattered across tools, seeing your real risk picture and proving you have treated it is far harder.

Turn your risk register into controls that run.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Treat the risks you identify with controls that actually operate, evidenced from one platform and mapped to ISO 27001. No security team required.

Book a Demo →

Frequently asked questions

What is an ISO 27001 risk assessment?

It is the process of identifying what could go wrong with the information you hold, scoring each risk by likelihood and impact, and recording the results in a risk register. Those results decide which Annex A controls you implement.

How do I run an ISO 27001 risk assessment?

Identify your assets, identify the threats to each, score likelihood and impact, prioritise by combined risk, and record everything in a risk register. Then decide how to treat each risk, which drives your Statement of Applicability.

What is a risk register?

A living record of each identified risk, its score, its owner, and the planned treatment. It is the main output of the risk assessment and a document auditors review to confirm your process is real and maintained.

How is risk assessment linked to control selection?

Directly. Annex A is a menu of 93 controls; the risk assessment tells you which to select. Every control you include should trace back to a risk, and that logic is recorded in the Statement of Applicability.

How often should I redo the risk assessment?

Revisit it on a schedule and whenever something material changes, a new system, new data types, or a new threat. A stale assessment and register are common causes of findings at the surveillance audit.