ISO 27005:2022
Context establishment – ISO 27005:2022

ISO 27005:2022 6.4.3.2: Consequence criteria

Consequence criteria express the extent of damage, loss or harm to the organisation or individuals when in-scope information loses its confidentiality, integrity or availability, with particular regard to: loss of life or harm to people or groups; loss of freedom, dignity or privacy; loss of staff and intellectual capital; disrupted internal or third-party operations; effects on plans and deadlines; loss of business or financial value; reduced market share or competitive advantage; harm to reputation or to public trust; failure to meet legal, statutory or regulatory requirements; failure to honour contracts or service levels; adverse effects on interested parties; and harm to the environment or pollution. The organisation settles how many consequence categories there are, how each is defined and what belongs in it, fitted to its context. A monetary scale can be bounded by the largest annual write-off it will bear and the smallest loss that would force liquidation, then divided into categories reflecting its risk perception and appetite, commonly on a logarithmic scale though other schemes may fit better. Where departments express consequences differently, cross-referencing them to a common anchoring scale keeps comparable levels comparable and allows aggregation across domains; a data breach, for instance, can touch privacy, confidentiality, integrity or availability and data protection compliance at once.

Maintained by Gerard Blokdyk

Other controls in Context establishment – ISO 27005:2022

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.