Book
ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks
by ISO/IEC · 2022 · 1 reading card
1 card
ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks · 2022
Criteria are written before the risks, otherwise the threshold moves to fit the result.
Clause 6.1.2 of ISO/IEC 27001:2022 asks for a process, not a spreadsheet. Item a) asks for written criteria: the risk acceptance criteria and the criteria for performing assessments. Item b) is the one that separates a serious method from improvisation — repeated assessments must produce consistent, valid and comparable results. Then come identification of risks to confidentiality, integrity and availability together with named risk owners; analysis, meaning the potential consequences, the realistic likelihood and the resulting levels of risk; and evaluation, meaning the first comparison against the criteria from item a) and the prioritization for treatment. The detailed guidance sits in ISO/IEC 27005:2022, the fourth edition, which contrasts two ways of identifying risk: the event-based approach, which starts from scenarios and the objectives at stake, and the classic asset-based approach, which starts from an inventory, threats and vulnerabilities. The first is faster and closer to the business, the second more complete and slower.
“risk evaluation: process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its significance is acceptable or tolerable”