ISO 27001 clause guide
ISO 27001 Clause 6.1.2: Information security risk assessment
Define and apply a repeatable method for identifying, analysing and evaluating information-security risks so results remain reasonably consistent over time. This guide explains how to turn the clause into decisions, operating evidence and a defensible audit trail.
- Clause
- 6.1.2
- Theme
- Planning
- Primary outcome
- Use a repeatable method to identify, analyze, evaluate and own information-security risk.
What Clause 6.1.2 means in practice
Use a repeatable method to identify, analyze, evaluate and own information-security risk. Treat the clause as part of a management system rather than an isolated document request. Its outputs should influence connected decisions, and later records should show that those decisions were carried out.
The level of formality should match risk and complexity. What matters is clarity, consistency and a traceable connection between the organization’s circumstances, chosen approach and observed result.
Step-by-step implementation
- Step 1. Define a risk assessment methodology, likelihood and impact criteria, calculation method and risk acceptance criteria.
- Step 2. Identify relevant assets, processes or scenarios and consider confidentiality, integrity and availability.
- Step 3. Assign risk owners, analyse realistic consequence and likelihood, evaluate priorities and retain results.
- Final step. Test a recent example, record the result and improve weak handoffs or decisions.
Ownership
- Risk owners
- ISMS manager
- Security and service owners
Evidence and records
Implementation evidence
- information security risk assessment methodology
- risk criteria and matrix
- risk register
- asset or process inventory
- assigned risk owners and approved assessment results
Effectiveness evidence
- assessments produce comparable decisions across teams
- risk changes, incidents and control evidence update ratings and treatment
A document can show intent. A complete sample also shows who made the decision, what happened next, whether the result was reviewed and how exceptions were handled.
How an auditor may test Clause 6.1.2
- Select a current business or ISMS example affected by the clause.
- Confirm the method, criteria, owner and required output.
- Trace the example through its decision records and connected processes.
- Corroborate the record with operational evidence or participant interviews.
- Follow an exception, change or adverse result to its accountable conclusion.
- Check that review and improvement occur when circumstances or results change.
Questions to prepare for
- How do you identify information-security risks?
- How were likelihood, impact and acceptance criteria established?
- How do you ensure different assessments use the method consistently?
- Show me a recent risk assessment and how its owners were assigned.
Worked example
A customer portal risk links an internet-facing vulnerability, account takeover scenario, business impact, existing controls, likelihood and accountable owner.
A strong audit trail would identify the trigger, relevant information, accountable participants, decision, resulting actions and later verification. It should be possible to explain why the approach was reasonable without reconstructing it from memory.
Smaller and mature implementation approaches
Smaller organization
Use existing leadership, service-management or risk meetings, assign a named owner and retain concise decision records. Avoid parallel governance where an established process can produce the required outcome.
Mature or complex organization
Define group-wide criteria, delegated accountabilities, integrated workflow, quality checks and consolidated performance reporting while preserving local context and evidence.
Practical implementation checklist
- □ Define a risk assessment methodology, likelihood and impact criteria, calculation method and risk acceptance criteria.
- □ Identify relevant assets, processes or scenarios and consider confidentiality, integrity and availability.
- □ Assign risk owners, analyse realistic consequence and likelihood, evaluate priorities and retain results.
- □ A recent example has been traced through its connected ISMS processes.
- □ Weak results and overdue actions have accountable follow-up.
Common mistakes
- scoring risks without a documented methodology
- changing criteria between assessments
- omitting risk acceptance criteria
- treating vulnerability findings as complete risks
- failing to assign or involve risk owners
Frequently asked questions
Does ISO prescribe a 5×5 matrix?
No. Choose criteria that support consistent, understandable decisions in your organization.
What is the difference between likelihood and impact?
Likelihood considers how plausibly a scenario may occur; impact considers the consequences if it does.
Can a tool own a risk?
No. A person with authority should own the decision, even when a system stores the record.
How does this differ from Annex A 8.2?
Clause 6.1.2 defines the risk-assessment process; Annex A 8.2 addresses privileged access as a possible control.
Explore the clause in the interactive tool
Open Clause 6.1.2 in the free explainer to browse its connected clauses and implementation prompts.