A risk assessment is the process of working out what could go wrong with the information you hold, how likely it is, and how much it would cost you if it happened.
The short answer
An information security risk assessment identifies the risks to your information, analyses each one by likelihood and consequence, and evaluates the results against criteria you set in advance. It produces a prioritised risk register with a named owner for each risk. Under ISO 27001 it is required by Clause 6.1.2.
It is the step everything else depends on. Controls are selected because a risk assessment said so, and the Statement of Applicability records that reasoning. Skip it and the rest of the ISMS has nothing to stand on.
On this page
The four steps
What goes in the risk register
One row per risk. The register is the working document; the assessment is the process that fills it.
| Field | Example |
|---|---|
| Risk description | Customer data exposed through an over-permissive storage bucket |
| Asset affected | Production object storage holding customer uploads |
| Likelihood | Medium, based on rate of infrastructure change |
| Consequence | High, regulatory exposure and contractual breach |
| Risk level | High, above the acceptance threshold |
| Risk owner | A named individual, not a team |
Name a person, not a department
ISO 27001 requires risk owners, and “Engineering” is not an owner. Auditors check that the named individual knows they own the risk and can describe what they decided about it.
Setting criteria first
Criteria are agreed before any risk is scored, so the scoring cannot be adjusted afterwards to produce a convenient answer. Two things need defining: the scale used for likelihood and consequence, and the level above which a risk cannot simply be accepted.
Most small teams use a three-point or five-point scale. Precision matters far less than consistency, since the purpose is to rank risks against each other rather than to produce an absolute number.
How Osto supports it
A risk assessment is only as good as the picture of your environment behind it. Osto supplies that picture: discovered assets, cloud misconfigurations, vulnerability findings, access and identity data, all from one platform. The scoring, ownership and acceptance decisions remain yours, because they reflect your own tolerance for risk.
Free security assessment
Start with an accurate picture of your risk
Discovered assets, cloud misconfigurations, vulnerabilities and access data from one platform, ready to feed your assessment.
Get a free security assessment Book a platform walkthroughFree security assessment · No agents to wire up · One platform, everything
Frequently asked questions
What is a risk assessment in information security?
It is the process of identifying what could go wrong with the information an organisation holds, analysing each risk by likelihood and consequence, and evaluating the results against criteria set in advance. The output is a prioritised risk register with a named owner for each risk.
How is it different from a vulnerability assessment?
A vulnerability assessment finds technical weaknesses in systems. A risk assessment is broader and considers business consequence, including risks with no technical component at all, such as a key supplier failing or a departing employee retaining access.
How often should it be repeated?
At least annually, and whenever something significant changes: a new product, a new market, a major architectural change or a serious incident. ISO 27001 requires the assessment to be performed at planned intervals.
Do we need a formal methodology?
You need a documented and repeatable one. ISO 27005 offers guidance, but any method works provided the criteria are defined in advance and the same approach is applied consistently, so that repeating the assessment produces comparable results.

