Risk assessment and treatment is the engine of an ISO 27001 ISMS — it's what drives which controls you implement and why. Get it right and everything downstream (your SoA, your controls, your audit) follows logically. Get it wrong and you'll over-engineer, under-protect, or fail your audit. This hub covers the full risk cluster: methodology, register, treatment, the qualitative-vs-quantitative and asset-vs-scenario choices, acceptance criteria, ownership, common mistakes, and the standards that guide it all.
← Back to ISO 27001: The Complete Guide
Core how-to guides
Guide | What you'll learn |
|---|---|
The complete Clause 6.1.2 process, with a worked example | |
Fields, scoring, and keeping it living | |
Turning risk decisions into controls and the SoA | |
Setting thresholds and risk appetite | |
Who owns risk and signs off residual risk |
Choosing your approach
Guide | The decision |
|---|---|
How to score risk | |
How to identify risk |
Getting it right & the guiding standards
Guide | What you'll learn |
|---|---|
The pitfalls that fail audits — and fixes | |
RCA that satisfies auditors | |
Aligning with enterprise risk management | |
The optional guidance standard for IS risk |
