ISO 27005:2022
Information security risk assessment process – ISO 27005:2022

ISO 27005:2022 7.3.3: Assessing likelihood

Input: the scenarios with risk sources, business processes and objectives, likelihood criteria and the existing controls' effectiveness and status. Action: assess the likelihood of possible or actual scenarios on the established criteria. Trigger: not done before; scope or context changes; vulnerabilities found in implemented controls; unexpected control test or audit results; or changes in the threat environment such as new actors. Output: scenarios with their likelihoods. Likelihood reflects how often risk sources arise or how easily weaknesses can be exploited, considering experience and statistics; for deliberate sources, attackers' motivation (such as cost-benefit), changing capability and resources, influences such as organised crime, terrorism or foreign intelligence, and how attractive and vulnerable the information looks; for accidental sources, geography (nearby hazardous sites), natural disasters (earthquakes, flooding, tsunami, volcanic activity, extreme weather) and factors affecting human error and equipment malfunction; known weaknesses and compensating controls singly and together; and how well existing controls reduce known weaknesses. Estimates are inherently uncertain, from personal (the assessor's heuristics), methodological (simplified tools) and systemic (limited knowledge of the event) sources; reliability improves with team rather than individual assessment, external sources such as breach reports, scales with fitting range and resolution, and concrete categories (once a year rather than infrequent). Dependent events are conditioned on each other and need not be assessed separately, while independent events all contribute; dependencies within a scenario are identified first and independent events assessed first, and business-level likelihood is better built up from assessed lower-level contributory events than estimated in one step.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • BIMCO-4 Chapter 4: Assessing the likelihood

ISO 19011:2018 · 1 control

  • 5.5.5 Assigning responsibility for an individual audit to the audit team leader

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Information security risk assessment process – ISO 27005:2022

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.