Step 4 · Risks

Risk assessment What can go wrong and what it would cost.

A risk assessment answers what can happen, how likely it is and what the consequences would be. It is the core of every ISMS and an obligation under NIS2.

What it is about

ISO/IEC 27001 clause 6.1.2 requires a defined method with risk acceptance criteria that produces consistent, valid and comparable results when repeated. Risks are identified, assigned to risk owners, analysed and evaluated. Clause 8.2 requires the assessment to be repeated at planned intervals and when significant changes occur.

Step 4Risks
Likelihood →Impact →
  • before treatment
  • after

Sample values

How to go about it

  1. 01

    Define the method and the risk acceptance criteria.

  2. 02

    Identify risks per service and asset, across all hazards.

  3. 03

    Assess likelihood and impact.

  4. 04

    Name risk owners and prioritise the results.

Common mistakes

  • A risk list without a method: the ratings are not comparable.
  • Only cyber attacks, no outages from power, staff or suppliers.
  • Created once, never updated.

What an auditor wants to see

  • Documented method with acceptance criteria
  • Risk register with risk owners
  • Evidence of regular repetition

How UniqSuite helps

Ratings in UniqSuite follow fixed rules. Two people who answer the same way get the same result. You generate the risk report as PDF, Word or Excel.

References

  • ISO/IEC 27001, clauses 6.1.2 and 8.2
  • Section 30(1) and (2) No. 1 BSIG
  • ISO/IEC 27005 as guidance

Frequently asked questions

Which method is the right one?

The standard does not prescribe one. What matters is that it is documented and gives reproducible results. A simple likelihood-impact matrix is often enough.

How often is the assessment repeated?

At planned intervals, in practice usually once a year, and always after significant changes.

Who is a risk owner?

The person or entity with the accountability and authority to manage a risk. This is usually a manager in the business area who can decide on resources.

Do we have to assess risks per asset?

No. Since the 2013 edition, ISO 27001 no longer requires an asset-based approach; scenarios per service or process are also possible. The inventory still helps you not to miss anything.

Can we use the BSI method?

Yes. BSI Standard 200-3 describes a risk analysis based on IT-Grundschutz. What matters is that your method meets the requirements of clause 6.1.2, such as defined risk acceptance criteria.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.