ISO 27001 · Domain 3
Risk Assessment and Treatment
About 25% of the exam
The 6.1.2 and 6.1.3 sequence
- Define risk criteria
- Identify risks
- Analyze consequence and likelihood
- Evaluate against criteria
- Choose treatment options
- Determine necessary controls
- Compare with Annex A
- Produce the SoA
- Approve and accept
- 6.1.2 a
- acceptance and assessment criteria set
- 6.1.2 c
- identify risks to confidentiality, integrity, availability
- 6.1.2 d
- analyze consequence, likelihood and level
- 6.1.2 e
- evaluate and prioritize for treatment
- 6.1.3 b
- determine the controls that are necessary
- 6.1.3 c
- compare that set against Annex A
- 6.1.3 d
- produce the Statement of Applicability
- 6.1.3 e
- formulate the risk treatment plan
- 6.1.3 f
- owner approves plan and residual risk
Controls are determined first and only then compared with Annex A, never picked off the list and justified backwards
Risk criteria
- Acceptance criteria written before assessing
- Scales defined with anchored descriptions
- Criteria approved, not invented per risk
- Same criteria across the whole scope
- Reviewed when appetite or context shifts
Who owns what
- Risk owner
- accountable for the risk itself
- Control owner
- runs the control day to day
- Asset owner
- knows value and dependencies
- Top management
- sets appetite and funds treatment
- Internal auditor
- tests the process, not the risk
Treatment options
- Modify
- add or strengthen controls
- Avoid
- stop the activity creating the risk
- Share
- insurance, outsourcing or contract terms
- Retain
- accept knowingly, inside the criteria
- Pursue
- take risk to chase an opportunity
- Combination
- one risk may need several
Sharing moves consequence, never accountability; the risk owner still answers for the outcome
Statement of Applicability, field by field
- Control reference
- the Annex A identifier
- Applicable
- a yes or no decision
- Inclusion reason
- risk, legal duty or contract
- Exclusion reason
- why the control is unnecessary
- Status
- implemented, partial or planned
- Link
- which risk the control treats
- Review trigger
- any change to treatment decisions
All ninety three controls appear; a control can be applicable and not yet implemented, and the SoA must show that honestly
Asset based versus event based
- The 2022 edition dropped the mandated method
- Asset based starts from what you hold
- Event based starts from what could happen
- Either is allowed, or both together
- Method must be consistent and repeatable
Likelihood that is defensible
- Anchor each level to a frequency
- Use incident history where it exists
- Use threat intelligence for new attacks
- Avoid identical scores across a category
- Record the reasoning, not just the number
Residual risk
- What remains once treatment operates
- Compared against the acceptance criteria
- Accepted in writing by the risk owner
- A verbal sign off is a nonconformity
- Reassessed whenever controls change
When to reassess
- At the planned intervals you defined
- After a merger or new region
- After a significant security incident
- When a new threat emerges
- When scope or technology changes
- Not only before the certification audit
ISO/IEC 27005 vocabulary
- Threat
- potential cause of an incident
- Vulnerability
- weakness a threat can exploit
- Consequence
- the outcome if it happens
- Likelihood
- the chance of it happening
- Risk level
- consequence combined with likelihood
- Risk appetite
- how much risk is wanted
- Aggregation
- small risks that add up
Clause 8, doing the work
- 8.1
- plan, implement and control processes
- 8.2
- assess risk at planned intervals
- 8.3
- implement the risk treatment plan
- 8.2 records
- keep the assessment results
- 8.3 records
- keep the treatment results
- Outsourced work
- determined and controlled as well
Risk mistakes examiners love
- Controls picked from Annex A first
- Every risk scored the same way
- Treatment plan without owners or dates
- SoA marked implemented with no evidence
- Acceptance criteria written after the results
- Legal duty overridden by an accept decision
- Risk register never linked to the SoA
Risk treatment plan anatomy
- Each action tied to a named risk
- Single accountable owner per action
- Target date and milestone stated
- Resources and budget identified
- Expected residual risk after completion
- Progress reported into management review
- Approved by the relevant risk owner
- Retained as documented information
Rapid recall: risk terms
- Risk
- effect of uncertainty on objectives
- Control
- a measure that modifies risk
- Inherent risk
- before treatment is applied
- Residual risk
- what treatment leaves behind
- Risk criteria
- terms of reference for significance
- Risk owner
- accountable and authorized person
Where risk touches other clauses
- Clause 4
- context frames the risks
- Clause 5.3
- risk owners given authority
- Clause 6.2
- objectives consider risk results
- Clause 8.2
- assessment at planned intervals
- Clause 9.1
- measure whether treatment worked
- Clause 10.2
- corrective action updates the risks
Reference strip: criteria, options, SoA, records, triggers
Criteria
- Acceptance thresholds set first
- Anchored likelihood and consequence scales
- Consistent, valid, comparable results
Options
- Modify, avoid, share, retain
- Pursue when opportunity outweighs risk
- Owner approves the chosen option
SoA
- Every Annex A control listed
- Inclusion and exclusion both justified
- Status linked to treatment decisions
Records
- Risk assessment process and results
- Treatment plan and its results
- Written residual risk acceptance
Triggers
- Planned intervals under clause 8.2
- Significant change or incident
- New legal or contractual duty
Quick exam traps
- Trap: Controls are selected from Annex A and the risks written afterwards
- Trap: Any manager may accept a residual risk on the spot
- Trap: The 2022 edition still requires the asset, threat and vulnerability method
- Trap: Sharing a risk through insurance transfers accountability as well
- Trap: A control marked applicable in the SoA is automatically implemented
- Trap: Risk assessment is only needed once a year before the audit
- Trap: A risk below the acceptance threshold can ignore a legal requirement
cybercertprep.com · original revision sheet written from the public body of knowledge