Step 4 · Risks
Risk assessment What can go wrong and what it would cost.
A risk assessment answers what can happen, how likely it is and what the consequences would be. It is the core of every ISMS and an obligation under NIS2.
What it is about
ISO/IEC 27001 clause 6.1.2 requires a defined method with risk acceptance criteria that produces consistent, valid and comparable results when repeated. Risks are identified, assigned to risk owners, analysed and evaluated. Clause 8.2 requires the assessment to be repeated at planned intervals and when significant changes occur.
- before treatment
- after
Sample values
How to go about it
- 01
Define the method and the risk acceptance criteria.
- 02
Identify risks per service and asset, across all hazards.
- 03
Assess likelihood and impact.
- 04
Name risk owners and prioritise the results.
Common mistakes
- A risk list without a method: the ratings are not comparable.
- Only cyber attacks, no outages from power, staff or suppliers.
- Created once, never updated.
What an auditor wants to see
- Documented method with acceptance criteria
- Risk register with risk owners
- Evidence of regular repetition
How UniqSuite helps
Ratings in UniqSuite follow fixed rules. Two people who answer the same way get the same result. You generate the risk report as PDF, Word or Excel.
References
- ISO/IEC 27001, clauses 6.1.2 and 8.2
- Section 30(1) and (2) No. 1 BSIG
- ISO/IEC 27005 as guidance
Frequently asked questions
Which method is the right one?
The standard does not prescribe one. What matters is that it is documented and gives reproducible results. A simple likelihood-impact matrix is often enough.
How often is the assessment repeated?
At planned intervals, in practice usually once a year, and always after significant changes.
Who is a risk owner?
The person or entity with the accountability and authority to manage a risk. This is usually a manager in the business area who can decide on resources.
Do we have to assess risks per asset?
No. Since the 2013 edition, ISO 27001 no longer requires an asset-based approach; scenarios per service or process are also possible. The inventory still helps you not to miss anything.
Can we use the BSI method?
Yes. BSI Standard 200-3 describes a risk analysis based on IT-Grundschutz. What matters is that your method meets the requirements of clause 6.1.2, such as defined risk acceptance criteria.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
