Step 4 of 6 · Plan

Risks What could happen, and how bad it would be.

Every gap becomes a risk. You assess how likely damage is and how serious it would be, and decide what to do about it.

Risks – screen in UniqSuite
Screenshot from a demo tenant with made-up data.

What it is about

Not every gap is equally dangerous. A missing policy weighs differently from an unprotected remote access. The risk analysis makes sure you spend time and money where it makes the biggest difference, and that you can justify that decision.

How you go about it

  1. UniqSuite suggests a risk for each gap. You accept it, adjust it or add your own.
  2. You rate likelihood and impact on a fixed scale.
  3. For each risk you choose a treatment: reduce, avoid, transfer or consciously accept.

What UniqSuite does for you

  • The assessment follows fixed rules. Two people who answer the same way reach the same result.
  • You create the risk report at the push of a button as PDF, Word or Excel.

What you end up with

A risk report with assessed risks and the treatment chosen for each.

Where the requirements come from

  • ISO/IEC 27001, clause 6.1.2: information security risk assessment
  • ISO/IEC 27001, clause 6.1.3: information security risk treatment
  • BSIG section 30(1) and (2) no. 1: risk management measures and policies on risk analysis

The references show where the requirements come from. They do not replace a legal assessment.

How far along are you with this step?

The quick check shows you in two minutes. Or let us show you UniqSuite with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy notice.