Skip to content
Log inRegister

ISO 27001 Risk Assessment

Dr. Abeer Alshammari · Published 7/29/2026

IntermediateProfessionalsCISOs

ISO 27001 does not prescribe a specific risk assessment methodology -- it requires that you have a consistent, repeatable, documented one that identifies risks to confidentiality, integrity, and availability of information.

The process, at a minimum

  • Establish and document risk criteria (how likelihood and impact are rated, and what counts as an "acceptable" risk level)
  • Identify risks -- typically through asset identification, threat identification, and vulnerability identification
  • Analyze and evaluate risk against the established criteria
  • Identify risk treatment options and select applicable Annex A controls (or other controls) to address them
  • Produce a risk treatment plan and get risk owner sign-off
  • Repeat on a defined cycle (typically annually, or when significant changes occur) -- risk assessment is not a one-time exercise

How this feeds the Statement of Applicability

The risk assessment output directly determines which Annex A controls are marked applicable in the SoA and why. An SoA that does not visibly trace back to risk assessment findings is a common audit finding -- auditors expect to see the logical thread from identified risk to selected control.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights