ISO 27001 Clause 8.2 Information Security Risk Assessment

Stuart Barker - ISO 27001 Ninja

ISO 27001 Clause 8.2 Information Security Risk Assessment

ISO 27001 Clause 8.2 Information Security Risk Assessment requires organisations to run risk assessments at planned intervals or following significant changes. Clear assessment processes identify threats, evaluate potential business impacts, and produce consistent, comparable results across the management system.

Key Takeaways

  • Execute planned risk assessments: Run formal risk evaluations on a defined schedule or whenever major operational changes occur.
  • Store records centrally: Keep risk assessment methodologies, criteria tables, and active risk registers in a central document repository.
  • Identify threats and vulnerabilities: Spot realistic threat events and system weaknesses that could harm confidentiality, integrity, or availability.
  • Assess operational impacts: Calculate potential damage by evaluating the likelihood of occurrence against business and legal consequences.
  • Ensure consistent scoring: Apply standard evaluation criteria to ensure assessments produce repeatable, comparable, and reliable results.
  • Assign named risk owners: Designate specific operational leads to validate risk scores and take accountability for identified risks.
  • Compare against risk criteria: Evaluate calculated risk levels against established risk acceptance thresholds to prioritize treatment needs.
  • Retain documented assessment proof: Maintain evidence of assessment execution, analysis workings, and owner sign-offs for audit verification.

How to Implement ISO 27001 Clause 8.2

  • Draft a risk assessment policy: Write clear guidelines establishing your risk assessment framework and publish them in your central repository.
  • Define clear risk criteria: Set quantitative or qualitative scoring scales for likelihood, impact severity, and risk acceptance thresholds.
  • Identify information assets: Catalog core data assets, systems, personnel, and physical sites subject to potential security risks.
  • Map threats and vulnerabilities: Identify relevant threat sources and operational vulnerabilities associated with each recorded asset.
  • Calculate initial risk levels: Combine likelihood scores with business impact ratings to establish raw risk levels before treatment.
  • Engage business asset owners: Involve operational managers in scoring discussions to ensure ratings reflect real-world business realities.
  • Trigger ad-hoc assessments: Conduct immediate risk reviews whenever major system upgrades, office relocations, or restructuring happen.
  • Document assessment findings: Record all identified risks, calculated scores, and rationale notes inside your central risk register.
  • Feed results into treatment workflows: Pass all risks exceeding the acceptance line directly into the risk treatment process.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Clause 8.2

  • Review risk assessment procedures: Inspect written guidelines to confirm defined criteria govern risk identification, analysis, and evaluation.
  • Sample active risk register entries: Check sampled risks to verify scores follow approved likelihood and impact calculation scales.
  • Verify assessment consistency: Compare multiple completed risk evaluations to confirm different teams apply criteria consistently without bias.
  • Inspect change-triggered reviews: Verify teams conducted ad-hoc risk assessments following recent major infrastructure or operational changes.
  • Check risk owner involvement: Confirm named risk owners reviewed, approved, and validated risk ratings within their operational domains.
  • Cross-reference threat sources: Confirm the assessment considers emerging industry threats, legal duties, and incident history.
  • Interview operational managers: Speak with asset leads to verify they understand how risk scores were determined for their units.
  • Verify assessment review dates: Check logs to confirm management completed full risk assessment reviews within planned calendar intervals.

Audit Evidence Checklist

  • Risk assessment methodology: Maintain a documented procedure defining scoring scales, impact definitions, and evaluation rules.
  • Central information risk register: Supply an up-to-date register detailing identified threats, vulnerabilities, scores, and risk owners.
  • Risk assessment reports: Provide completed evaluation summaries produced during scheduled annual or change-driven risk reviews.
  • Risk owner sign-off records: Supply approval logs showing risk owners agreed with assigned likelihood and impact scores.
  • Change-driven risk assessments: Maintain risk assessment records executed for major project launches or system modifications.
  • Risk criteria approval notes: Provide records showing executive leadership reviewed and approved risk acceptance thresholds.
  • Management review risk summaries: Provide meeting minutes demonstrating leaders reviewed risk assessment outputs.

What to Teach Employees

  • Recognise operational risks: Teach workers how to spot daily security threats, procedural flaws, and data handling vulnerabilities.
  • Report new threats fast: Instruct staff to notify risk leads whenever business changes create unassessed security risks.
  • Understand risk scoring: Educate team leads on how likelihood and business impact combine to generate overall risk levels.
  • Participate in risk workshops: Encourage workers to share honest operational experiences during risk assessment interviews.
  • Know your assigned risks: Ensure risk owners understand which specific risk scenarios sit within their operational remit.
  • Support assessment updates: Remind teams that launching new projects or tools requires updating the central risk register.

Common Implementation Challenges

  • Treating assessments as annual tick-boxes: Running reviews once a year and ignoring changes in between. Trigger mini-reviews for all major changes.
  • Subjective and inconsistent scoring: Different assessors assign wildly different ratings to similar risks. Define rigid scoring matrices with concrete examples.
  • Assessing IT risks while ignoring data: Focusing solely on server hardware and forgetting business processes. Assess information assets and workflows first.
  • Risk registers disconnected from reality: Completing spreadsheets without consulting asset owners. Conduct collaborative workshops with operational teams.
  • Overly complex calculation formulas: Using confusing mathematical algorithms that alienate business owners. Use clear, accessible three-by-three or five-by-five scoring grids.
  • Failing to record rationale notes: Storing raw numbers without explaining why a score was chosen. Require written justifications for all assigned ratings.

How to Measure Effectiveness (KPIs)

  • Risk assessment review compliance: Track the percentage of identified information assets with risk assessments completed on schedule.
  • Change-driven assessment rate: Measure the proportion of major operational changes that completed a documented risk review before launch.
  • Unidentified risk incident rate: Track the number of security incidents caused by threats not previously captured in the risk register.
  • Risk owner validation rate: Track the percentage of risk register entries formally reviewed and validated by named risk owners.
  • Assessment methodology consistency: Measure the proportion of departmental risk registers matching approved corporate scoring criteria.
  • Risk assessment audit finding count: Monitor the number of non-conformities raised against risk assessment execution during internal and external audits.

ISO 27001 Clause 8.2 connects to several other ISO 27001 requirements:

  • ISO 27001 Clause 6.1.2: This provides the methodology that you must follow in Clause 8.2.
  • ISO 27001 Annex A 5.12: Information classification helps determine the “Impact” score during your risk assessment.
  • ISO 27001 Annex A 8.8: Vulnerability management provides the technical data needed to assess the “Likelihood” of a risk.