markdowneditor

Risk Assessment & Treatment Methodology

Repeatable risk assessment + treatment process

ISO та комплаєнсСтандартriskmethodology

Як використовувати: Write once, run each cycle. Define the acceptance threshold before scoring, or scoring gets negotiated.

Перегляд

Risk Assessment & Treatment Methodology

Mandatory – ISO/IEC 27001:2022 cl.6.1.2 (define and apply the process repeatedly) + ISO 31000-aligned. Write this ONCE; run it per cycle.

FieldValue
Document IDDOC-ISMS-010
Approved byRisk owner / management
EffectiveYYYY-MM-DD

1. Risk criteria (cl.6.1.2 a)

Acceptance threshold, scales, and who can accept:

LevelLikelihood (1-5)Impact (1-5)Score = L×IAction
Low11-21-4Accept, monitor
Medium2-32-35-9Evaluate treatment
High4-53-410-19Treat, plan required
Critical5520-25Immediate action, escalate

2. Assessment process (repeatable)

  1. Identify – risk = asset × threat × vulnerability scenario
  2. Analyze – score likelihood × impact per scale above
  3. Evaluate – compare to acceptance criteria → prioritize

Asset × scenario catalog

AssetThreatVulnerabilityScenario
Data/systemthreat classweaknessCIA impact description

3. Treatment options (cl.6.1.3)

OptionWhen usedHow recorded
Mitigate (controls)risk > appetiteAnnex A control in SoA
Avoidactivity too riskystop the activity
Transferinsurablecontract/insurance
Acceptwithin criteriawritten acceptance by owner

4. Roles

  • Risk owner: accountable for the risk and its treatment
  • Assessor: performs scoring
  • Approver: signs treatment plan (management)

5. Outputs produced per cycle

  • Risk assessment report (cl.8.2)
  • Risk register (updated)
  • Risk treatment plan (cl.6.1.3 e)
  • Statement of Applicability (cl.6.1.3 d)

6. Review cycle

Annually + on significant change (incident, new system, org change).

Схожі шаблони