IS Risk Assessment
EN RU

Risk assessment method

According to ISO/IEC 27005:2022, risk assessment consists of three consecutive activities. Each of them adds new columns to your list of risks.

  1. 1Risk identificationList of risks + risk owners
  2. 2Risk analysis+ consequences + likelihood + level of risk
  3. 3Risk evaluation+ acceptable or not + priority
0

Context establishment

Before the assessment, define what is assessed and by which criteria. In this workbook you do it when creating a risk list.

1

Risk identification

Find, recognise and describe the risks: events that can prevent, affect or delay the achievement of information security objectives. A risk that is not identified at this stage is lost for further analysis.

2

Risk analysis

The goal is to determine the level of each risk. The level of risk is a combination of consequences and likelihood.

3

Risk evaluation

Compare the results of the analysis with the criteria defined in advance and decide what to do next.

How the system suggests the level of risk

For qualitative scales a risk matrix is used. The suggestion is only a hint — the final level is your decision.

high / medium / low

High Medium High High
Medium Low Medium High
Low Low Low Medium
LowMediumHigh

Rows — likelihood, columns — severity of consequences.

very high / high / medium / low / negligible

Very high Low Medium High Very high Very high
High Low Medium High High Very high
Medium Low Medium Medium High High
Low Negligible Low Medium Medium Medium
Negligible Negligible Negligible Low Low Low
NegligibleLowMediumHighVery high

Rows — likelihood, columns — severity of consequences.

For quantitative scales the level is the normalised product: consequences × likelihood ÷ maximum of the scale. For example, on the 0–10 scale consequences 8 and likelihood 5 give the level 4.

Go to my risk lists