ISO 27001 Risk Assessment
Dr. Abeer Alshammari · Published 7/29/2026
IntermediateProfessionalsCISOs
ISO 27001 does not prescribe a specific risk assessment methodology -- it requires that you have a consistent, repeatable, documented one that identifies risks to confidentiality, integrity, and availability of information.
The process, at a minimum
- Establish and document risk criteria (how likelihood and impact are rated, and what counts as an "acceptable" risk level)
- Identify risks -- typically through asset identification, threat identification, and vulnerability identification
- Analyze and evaluate risk against the established criteria
- Identify risk treatment options and select applicable Annex A controls (or other controls) to address them
- Produce a risk treatment plan and get risk owner sign-off
- Repeat on a defined cycle (typically annually, or when significant changes occur) -- risk assessment is not a one-time exercise
How this feeds the Statement of Applicability
The risk assessment output directly determines which Annex A controls are marked applicable in the SoA and why. An SoA that does not visibly trace back to risk assessment findings is a common audit finding -- auditors expect to see the logical thread from identified risk to selected control.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon