ISO 27001 Risk Assessment: Method, Example and Template
ISO 27001 risk assessment for SMEs: define criteria, analyse and treat risks, and connect decisions with controls and evidence.
An ISO 27001 risk assessment makes information risks comparable and actionable. A sound method defines scope, criteria, owners and review triggers. It does not jump from a threat to an arbitrary control; it links a justified treatment decision to specific measures and evidence.
What is assessed
The starting point can be information assets, business processes or scenarios. A scenario-based approach is often easier for SMEs: what could happen, which information or service would be affected, what cause is credible and what would the impact be on confidentiality, integrity or availability?
A practical six-step method
- Define scope and unit of assessment
- Describe scenarios using cause, event and impact
- Assess likelihood and impact against defined scales
- Consider existing controls and their effectiveness
- Choose treatment: avoid, reduce, transfer or accept
- Record residual risk, owner, measures, dates and evidence
Example risk-register entry
| Field | Example |
|---|---|
| Scenario | Unauthorised access to customer files after a role change |
| Impact | Confidentiality breach and customer notification |
| Existing control | Offboarding checklist |
| Assessment | Elevated because access reviews are not performed regularly |
| Treatment | Quarterly access reviews and automated deprovisioning |
| Owner / date | Head of IT / Q3 |
| Residual risk | Acceptable after effectiveness review |
Turning assessment into control
A risk register is useful only when actions are tracked and effectiveness is tested. Link each treated risk to the treatment plan, Statement of Applicability and verifiable evidence.
The method should be repeatable. New systems, material supplier changes, incidents or scope changes are common triggers for an additional review.
How Sternberg Consulting supports you
We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.
Frequently asked questions
Does every asset need a separate risk?
No. Granularity must remain manageable, and one scenario may affect several assets or processes.
Can management accept risks?
Yes, when acceptance criteria are defined, the decision is authorised and legal or contractual duties are not breached.
Is a spreadsheet enough?
Often yes for an SME, provided version control, ownership, follow-up and access protection work.