ISO 27005:2022
Context establishment – ISO 27005:2022

ISO 27005:2022 6.4.3.3: Likelihood criteria

Likelihood criteria depend on: accidental or natural events; how exposed the information or related asset is to the threat; how far the organisation's vulnerability is exploited; technology failure; and human acts or omissions. Likelihood can be stated as a probability of occurrence within a period or as a frequency (average number of occurrences in a period); frequency is easier to communicate but only probabilities can be aggregated. The criteria cover the range of likelihoods that can realistically be managed; beyond it, noting that a limit has been passed (an extreme case) is usually enough. Scales that are too wide quantise coarsely and cause error, especially at the top of exponential scales where steps are very large, and primary attention goes to risk sources whose likelihoods matter most in the organisation's context and ISMS scope.

Maintained by Gerard Blokdyk

Other controls in Context establishment – ISO 27005:2022

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.