{"id":663,"date":"2026-08-13T07:53:47","date_gmt":"2026-08-13T07:53:47","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=663"},"modified":"2026-08-13T07:53:47","modified_gmt":"2026-08-13T07:53:47","slug":"risk-assessment","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/","title":{"rendered":"Risk Assessment: Steps and the Risk Register"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: RISK ASSESSMENT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A risk assessment is the process of working out what could go wrong with the information you hold, how likely it is, and how much it would cost you if it happened.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>An information security risk assessment identifies the risks to your information, analyses each one by likelihood and consequence, and evaluates the results against criteria you set in advance. It produces a prioritised risk register with a named owner for each risk. Under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> it is required by Clause 6.1.2.<\/p>\n<\/div>\n\n<p>It is the step everything else depends on. Controls are selected because a risk assessment said so, and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> records that reasoning. Skip it and the rest of the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> has nothing to stand on.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#steps\">The four steps<\/a><\/li>\n    <li><a href=\"#register\">What goes in the risk register<\/a><\/li>\n    <li><a href=\"#criteria\">Setting criteria first<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports it<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"steps\">The four steps<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 165\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Risk assessment steps: set criteria, identify risks, analyse likelihood and consequence, evaluate and prioritise.\">\n  <defs><marker id=\"raA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"34\" width=\"168\" height=\"82\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"94\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">1. Set criteria<\/text>\n  <text x=\"94\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">What counts as high,<\/text>\n  <text x=\"94\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">and what you accept<\/text>\n  <line x1=\"184\" y1=\"75\" x2=\"198\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#raA)\"\/>\n\n  <rect x=\"204\" y=\"34\" width=\"168\" height=\"82\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"288\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">2. Identify<\/text>\n  <text x=\"288\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">What could happen to<\/text>\n  <text x=\"288\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">which information<\/text>\n  <line x1=\"378\" y1=\"75\" x2=\"392\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#raA)\"\/>\n\n  <rect x=\"398\" y=\"34\" width=\"168\" height=\"82\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"482\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">3. Analyse<\/text>\n  <text x=\"482\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Likelihood and<\/text>\n  <text x=\"482\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">consequence<\/text>\n  <line x1=\"572\" y1=\"75\" x2=\"586\" y2=\"75\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#raA)\"\/>\n\n  <rect x=\"592\" y=\"34\" width=\"158\" height=\"82\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"671\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">4. Evaluate<\/text>\n  <text x=\"671\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Rank against your<\/text>\n  <text x=\"671\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">criteria, assign owners<\/text>\n\n  <text x=\"380\" y=\"148\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">The output is a prioritised register. Deciding what to do about each risk is the risk treatment plan.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"register\" class=\"c-sage\">What goes in the risk register<\/h2>\n\n<p>One row per risk. The register is the working document; the assessment is the process that fills it.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Field<\/th><th>Example<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Risk description<\/strong><\/td><td>Customer data exposed through an over-permissive storage bucket<\/td><\/tr>\n    <tr><td><strong>Asset affected<\/strong><\/td><td>Production object storage holding customer uploads<\/td><\/tr>\n    <tr><td><strong>Likelihood<\/strong><\/td><td>Medium, based on rate of infrastructure change<\/td><\/tr>\n    <tr><td><strong>Consequence<\/strong><\/td><td>High, regulatory exposure and contractual breach<\/td><\/tr>\n    <tr><td><strong>Risk level<\/strong><\/td><td>High, above the acceptance threshold<\/td><\/tr>\n    <tr><td><strong>Risk owner<\/strong><\/td><td>A named individual, not a team<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Name a person, not a department<\/p>\n  <p>ISO 27001 requires risk owners, and &#8220;Engineering&#8221; is not an owner. Auditors check that the named individual knows they own the risk and can describe what they decided about it.<\/p>\n<\/div>\n\n<h2 id=\"criteria\" class=\"c-apri\">Setting criteria first<\/h2>\n\n<p>Criteria are agreed before any risk is scored, so the scoring cannot be adjusted afterwards to produce a convenient answer. Two things need defining: the scale used for likelihood and consequence, and the level above which a risk cannot simply be accepted.<\/p>\n\n<p>Most small teams use a three-point or five-point scale. Precision matters far less than consistency, since the purpose is to rank risks against each other rather than to produce an absolute number.<\/p>\n\n<h2 id=\"osto\">How Osto supports it<\/h2>\n\n<p>A risk assessment is only as good as the picture of your environment behind it. Osto supplies that picture: discovered assets, cloud misconfigurations, vulnerability findings, access and identity data, all from one platform. The scoring, ownership and acceptance decisions remain yours, because they reflect your own tolerance for risk.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Start with an accurate picture of your risk<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Discovered assets, cloud misconfigurations, vulnerabilities and access data from one platform, ready to feed your assessment.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Free security assessment &middot; No agents to wire up &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a risk assessment in information security?<\/summary>\n  <p>It is the process of identifying what could go wrong with the information an organisation holds, analysing each risk by likelihood and consequence, and evaluating the results against criteria set in advance. The output is a prioritised risk register with a named owner for each risk.<\/p>\n<\/details>\n\n<details>\n  <summary>How is it different from a vulnerability assessment?<\/summary>\n  <p>A vulnerability assessment finds technical weaknesses in systems. A risk assessment is broader and considers business consequence, including risks with no technical component at all, such as a key supplier failing or a departing employee retaining access.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should it be repeated?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-gap-analysis\/\">At least annually<\/a>, and whenever something significant changes: a new product, a new market, a major architectural change or a serious incident. ISO 27001 requires the assessment to be performed at planned intervals.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we need a formal methodology?<\/summary>\n  <p>You need a documented and repeatable one. ISO 27005 offers guidance, but any method works provided the criteria are defined in advance and the same approach is applied consistently, so that repeating the assessment produces comparable results.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-treatment-plan\/\">Risk Treatment Plan<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A Controls<\/a> &middot; Vulnerability Assessment<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A risk assessment is the process of working out what could go wrong with the information you hold, how likely\u2026<\/p>\n","protected":false},"author":8,"featured_media":664,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[243,242,245,244],"class_list":["post-663","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-information-security-risk-assessment","tag-risk-assessment","tag-risk-owner","tag-risk-register"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=663"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/663\/revisions"}],"predecessor-version":[{"id":665,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/663\/revisions\/665"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/664"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}