ISO 27001 Clause 6.1.2 Information Security Risk Assessment

ISO 27001 Clause 6.1.2 Information Security Risk Assessment

ISO 27001 Clause 6.1.2 Information Security Risk Assessment

ISO 27001 Clause 6.1.2 Information Security Risk Assessment requires organisations to define and apply a formal risk assessment process. Documented criteria ensure teams identify threats, evaluate potential business impacts, and establish consistent, repeatable risk scores across the business.

Key Takeaways

  • Establish a risk assessment framework: Create clear rules to identify, analyse, and evaluate information security risks systematically.
  • Store methodologies centrally: Keep risk assessment policies, scoring tables, and criteria registers in a central document repository.
  • Set explicit risk criteria: Define risk acceptance thresholds and impact scales before evaluating active operational threats.
  • Ensure repeatable scoring: Apply consistent calculation formulas so different assessors produce comparable, reliable results over time.
  • Identify risks to confidentiality, integrity, and availability: Spot potential threat events that could compromise critical business data and systems.
  • Assign named risk owners: Designate specific operational managers with the formal authority to manage and own identified risks.
  • Prioritise risks for treatment: Compare calculated risk levels against acceptance boundaries to determine which risks require treatment.
  • Retain documented assessment proof: Maintain detailed assessment registers and meeting logs to prove compliance during audits.

How to Implement ISO 27001 Clause 6.1.2

  • Draft a risk assessment methodology: Write a clear procedure detailing your risk scoring formulas, acceptance rules, and review cycles.
  • Define likelihood and impact scales: Create simple, standardized rating grids, such as low, medium, and high, or numeric one-to-five scales.
  • Set risk acceptance criteria: Establish the exact risk score above which risks must receive formal treatment safeguards.
  • Identify threats and vulnerabilities: Map realistic threat scenarios and operational weaknesses across all critical information assets.
  • Calculate raw risk scores: Multiply or combine likelihood and impact ratings to determine the initial risk level before safeguards.
  • Engage operational risk owners: Involve business department heads to validate scores and take ownership of identified risks.
  • Log findings in a central risk register: Record identified threat scenarios, asset links, assigned owners, and scores in a live tracker.
  • Trigger assessments on major changes: Run ad-hoc risk assessments whenever introducing new systems, suppliers, or business locations.
  • Feed results into risk treatment: Route all risks exceeding your acceptance threshold directly into the Clause 6.1.3 treatment workflow.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Clause 6.1.2

  • Review risk methodology documentation: Inspect written procedures to verify explicit rules define how the business identifies and analyses risks.
  • Audit risk acceptance criteria: Check that leadership defined and formally approved explicit risk acceptance thresholds.
  • Sample active risk register entries: Check sampled risks to ensure scoring calculations match the defined likelihood and impact scales.
  • Verify risk owner assignments: Confirm every logged risk links to an active, named individual with operational authority.
  • Inspect scoring consistency: Cross-check risk evaluations completed by different teams to ensure uniform application of scoring rules.
  • Check change-triggered assessments: Verify teams completed risk assessments before rolling out recent major operational or technical changes.
  • Interview risk owners: Speak with operational leads to confirm they understand how their assigned risks were identified and evaluated.
  • Confirm assessment intervals: Verify that management conducted scheduled risk assessments within planned calendar timeframes.

Audit Evidence Checklist

  • Risk assessment methodology document: Maintain a documented policy defining scoring scales, impact matrices, and evaluation criteria.
  • Approved risk criteria sign-off: Supply evidence showing top management reviewed and approved risk acceptance boundaries.
  • Central information risk register: Provide an active register containing identified threats, vulnerabilities, scores, and named risk owners.
  • Completed risk assessment reports: Provide summary reports and workshop notes from scheduled annual risk reviews.
  • Change-driven risk evaluations: Maintain assessment records executed for new project launches or operational restructuring.
  • Risk owner validation records: Supply approval logs showing risk owners verified and agreed with assigned risk ratings.
  • Management review meeting minutes: Provide records proving executive leadership reviewed risk assessment findings.

What to Teach Employees

  • Understand risk identification: Teach staff how to spot day-to-day security threats, weak controls, and data exposure points.
  • Know your role in assessments: Encourage workers to participate openly in risk workshops and explain operational realities.
  • Report new risks promptly: Instruct teams to notify risk managers whenever business processes or supplier arrangements change.
  • Understand risk scoring basics: Educate team leads on how likelihood and business impact combine to produce overall risk ratings.
  • Support assigned risk owners: Remind staff to help department leads manage and track operational risks effectively.
  • Follow established safeguards: Reiterate that security controls exist directly to mitigate identified assessment risks.

Common Implementation Challenges

  • Overly complex scoring algorithms: Creating complicated mathematical formulas alienates business managers. Use clean, accessible scoring matrices.
  • Subjective and biased ratings: Assessors score risks based on personal feelings rather than criteria. Provide detailed criteria definitions with concrete examples.
  • Assessing IT systems without business data: Focusing only on servers while ignoring core data workflows. Inventory information assets before evaluating risks.
  • Treating assessments as one-off exercises: Reviewing risks once for certification and shelving the register. Embed risk reviews into regular change management workflows.
  • Missing risk ownership: Logging risks without naming individual business owners. Mandate a specific named owner for every register entry.
  • Disconnect from risk treatment: Assessing risks without linking high scores to treatment plans. Automate escalation from assessment to treatment.

How to Measure Effectiveness (KPIs)

  • Assessment schedule completion rate: Track the percentage of scheduled departmental risk assessments completed on time.
  • Change assessment coverage: Measure the proportion of major operational and technical changes assessed for risk prior to launch.
  • Unidentified threat incident rate: Track the number of security incidents caused by threats not previously captured in the risk register.
  • Risk owner validation percentage: Measure the proportion of risk register entries verified and signed off by assigned risk owners.
  • Scoring consistency audit rate: Track the percentage of sampled risk assessments complying fully with approved corporate scoring criteria.
  • Risk assessment audit finding count: Monitor the number of non-conformities raised against risk assessment execution during internal and external audits.

ISO 27001 Clause 6.1.2 connects to several other ISO 27001 requirements: