Risk Assessment & Treatment Methodology
Repeatable risk assessment + treatment process
Як використовувати: Write once, run each cycle. Define the acceptance threshold before scoring, or scoring gets negotiated.
Перегляд
Risk Assessment & Treatment Methodology
Mandatory – ISO/IEC 27001:2022 cl.6.1.2 (define and apply the process repeatedly) + ISO 31000-aligned. Write this ONCE; run it per cycle.
| Field | Value |
|---|---|
| Document ID | DOC-ISMS-010 |
| Approved by | Risk owner / management |
| Effective | YYYY-MM-DD |
1. Risk criteria (cl.6.1.2 a)
Acceptance threshold, scales, and who can accept:
| Level | Likelihood (1-5) | Impact (1-5) | Score = L×I | Action |
|---|---|---|---|---|
| Low | 1 | 1-2 | 1-4 | Accept, monitor |
| Medium | 2-3 | 2-3 | 5-9 | Evaluate treatment |
| High | 4-5 | 3-4 | 10-19 | Treat, plan required |
| Critical | 5 | 5 | 20-25 | Immediate action, escalate |
2. Assessment process (repeatable)
- Identify – risk = asset × threat × vulnerability scenario
- Analyze – score likelihood × impact per scale above
- Evaluate – compare to acceptance criteria → prioritize
Asset × scenario catalog
| Asset | Threat | Vulnerability | Scenario |
|---|---|---|---|
| Data/system | threat class | weakness | CIA impact description |
3. Treatment options (cl.6.1.3)
| Option | When used | How recorded |
|---|---|---|
| Mitigate (controls) | risk > appetite | Annex A control in SoA |
| Avoid | activity too risky | stop the activity |
| Transfer | insurable | contract/insurance |
| Accept | within criteria | written acceptance by owner |
4. Roles
- Risk owner: accountable for the risk and its treatment
- Assessor: performs scoring
- Approver: signs treatment plan (management)
5. Outputs produced per cycle
- Risk assessment report (cl.8.2)
- Risk register (updated)
- Risk treatment plan (cl.6.1.3 e)
- Statement of Applicability (cl.6.1.3 d)
6. Review cycle
Annually + on significant change (incident, new system, org change).