ISO 27005:2022
Information security risk assessment process – ISO 27005:2022

ISO 27005:2022 7.2.1: Identifying and describing information security risks

Input: events, inside the organisation or beyond it, that could stand in the way of its information security objectives. Action: identify risks tied to loss of confidentiality, integrity and availability. Trigger: risk owners, interested parties or experts detect or seek new or changed events or situations. Output: a list of identified risks. Identification finds risk sources and events and lists the risks that could prevent, affect or delay the objectives. Two common approaches: event-based, building strategic scenarios from risk sources and the ways they exploit or act on interested parties to achieve what they want, drawing on top management's concerns, risk owners and the context of 27001 clause 4, often through interviews that also reveal risk owners, quick to reach critical risks and able to use historical data or, where data are lacking, expert judgement; and asset-based, building operational scenarios from assets, threats and vulnerabilities, identifying primary and supporting assets by type and priority with their dependencies and interactions, so that enumerating all valid combinations would in theory find every risk and support detailed treatment, with an asset list drawn up for later steps. The two differ mainly in the level at which identification starts and can describe the same scenario, one drilling down and the other building up; Annex A gives more. Identification is critical, since unidentified risks drop out of later analysis; it takes in risks regardless of whether the organisation controls their source, iterates from high-level to root causes for complex scenarios, and may use any other approach giving consistent, valid and comparable results. Risks need not follow a rigid structure and may overlap or be instances of wider risks, but controls are identified per individual risk; aggregation happens only where the risks bear on one another at the level of context being considered, since independent hazards to one site (flood, fire, power spikes, vandalism) need different controls even when combined for an overall figure.

Maintained by Gerard Blokdyk

Other controls in Information security risk assessment process – ISO 27005:2022

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.