From books

Risk assessment does not produce a list of fears but a comparison against criteria written in advance, which someone else can redo and get the same answer.

ISO/IEC · ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks · 2022 · ISO/IEC 27005:2022, 3.2.6 «risk evaluation» — definiție preluată din ISO Guide 73:2009, 3.7.1, modificată («significance» a înlocuit «magnitude»)2 minutes read
risk evaluation: process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its significance is acceptable or tolerableISO/IEC · ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks · 2022 · ISO/IEC 27005:2022, 3.2.6 «risk evaluation» — definiție preluată din ISO Guide 73:2009, 3.7.1, modificată («significance» a înlocuit «magnitude»)

Criteria are written before the risks, otherwise the threshold moves to fit the result.

Clause 6.1.2 of ISO/IEC 27001:2022 asks for a process, not a spreadsheet. Item a) asks for written criteria: the risk acceptance criteria and the criteria for performing assessments. Item b) is the one that separates a serious method from improvisation — repeated assessments must produce consistent, valid and comparable results. Then come identification of risks to confidentiality, integrity and availability together with named risk owners; analysis, meaning the potential consequences, the realistic likelihood and the resulting levels of risk; and evaluation, meaning the first comparison against the criteria from item a) and the prioritization for treatment. The detailed guidance sits in ISO/IEC 27005:2022, the fourth edition, which contrasts two ways of identifying risk: the event-based approach, which starts from scenarios and the objectives at stake, and the classic asset-based approach, which starts from an inventory, threats and vulnerabilities. The first is faster and closer to the business, the second more complete and slower.

Why it mattersIf two analysts in the same organization rank the same risks differently, item b) of clause 6.1.2 has already failed.

Criteriawritten inIdentificationand riskAnalysis:consequenceEvaluation:comparison
Order matters: criteria first, ranking last.

Back to the feed