Risk assessment method
According to ISO/IEC 27005:2022, risk assessment consists of three consecutive activities. Each of them adds new columns to your list of risks.
- 1Risk identificationList of risks + risk owners
- 2Risk analysis+ consequences + likelihood + level of risk
- 3Risk evaluation+ acceptable or not + priority
Context establishment
Before the assessment, define what is assessed and by which criteria. In this workbook you do it when creating a risk list.
- Describe the scope: the organisation, process or system, and its information security objectives.
- Choose one scale for the list: quantitative (0–10 or 0–100) or qualitative (3 or 5 levels).
- Define the risk acceptance criterion — the level up to which a risk can be accepted.
Risk identification
Find, recognise and describe the risks: events that can prevent, affect or delay the achievement of information security objectives. A risk that is not identified at this stage is lost for further analysis.
- Choose a threat from the FSTEC Threat Database or formulate the risk yourself.
- Identify the sources of the risk and the events that can trigger it (event-based approach — fast, strategic scenarios; asset-based approach — detailed: assets, threats, vulnerabilities).
- Name the risk owners: people who are accountable, have the authority to manage the risk and can make informed decisions.
Risk analysis
The goal is to determine the level of each risk. The level of risk is a combination of consequences and likelihood.
- Consequences: describe what can happen after the loss of confidentiality, integrity or availability; estimate the loss in money or time and the recovery costs; rate the severity on the scale.
- Likelihood: rely on statistics, the motivation and capabilities of attackers, accidental factors, known weaknesses and existing controls. Prefer team assessment, external sources and unambiguous categories (“once a year”).
- Level of risk: the system suggests a value from consequences and likelihood; you make the final decision.
Risk evaluation
Compare the results of the analysis with the criteria defined in advance and decide what to do next.
- Acceptable or not: apply the acceptance criterion, taking into account the degree of confidence in the assessment and the cumulative effect of frequent small events.
- Priority: risks that cannot be accepted are prioritised for treatment — the higher the level, the earlier the treatment.
- Sort the list by level, priority, owner or loss to study it and understand the overall picture.
How the system suggests the level of risk
For qualitative scales a risk matrix is used. The suggestion is only a hint — the final level is your decision.
high / medium / low
| High | Medium | High | High |
|---|---|---|---|
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
| Low | Medium | High |
Rows — likelihood, columns — severity of consequences.
very high / high / medium / low / negligible
| Very high | Low | Medium | High | Very high | Very high |
|---|---|---|---|---|---|
| High | Low | Medium | High | High | Very high |
| Medium | Low | Medium | Medium | High | High |
| Low | Negligible | Low | Medium | Medium | Medium |
| Negligible | Negligible | Negligible | Low | Low | Low |
| Negligible | Low | Medium | High | Very high |
Rows — likelihood, columns — severity of consequences.
For quantitative scales the level is the normalised product: consequences × likelihood ÷ maximum of the scale. For example, on the 0–10 scale consequences 8 and likelihood 5 give the level 4.