ISO 27001 guide · Clause 6
6.1.2 — Information security risk assessment
ISO 27001:2022 sub-clause 6.1.2 requires a consistent, repeatable risk assessment process: what it expects, and the evidence auditors will ask to see.
By Sentrix · Published 2026-07-16
The requirement that turns “we think we are secure” into a defensible, repeatable answer to “what could go wrong, and how badly.”
In plain language
Sub-clause 6.1.2 requires you to define and apply a consistent method for identifying your information security risks, estimating their severity and likelihood, and prioritizing them. The keyword is repeatable: two people applying your method to the same information should arrive at comparable results.
Why this requirement exists
You cannot protect what you have not identified. This requirement ensures your security decisions rest on a structured evaluation rather than intuition or the latest technology trend. It also enforces consistency over time: without a defined method, every re-assessment would produce different, uninterpretable results.
Scenario: a company invests heavily in a top-tier firewall because “that is what everyone does,” but has never assessed its risks. As a result, its real weak point — backups that are never tested and shared access credentials — stays ignored, until the day ransomware hits. A proper risk assessment would have surfaced those priorities first.
What the standard expects
The standard asks you to establish and maintain risk criteria, then apply a process that produces consistent, valid, and comparable results. In concrete terms, it expects five things: define your risk acceptance criteria and the criteria for performing assessments; identify the risks that threaten the confidentiality, integrity, and availability of your information within the ISMS scope; assign risk owners responsible for each one; analyze each risk by estimating its potential consequences and likelihood; then evaluate the results against your criteria to establish treatment priorities. You are free to choose the method (asset-based, scenario-based, qualitative, or quantitative), as long as it is defined and applied consistently.
In practice
- Choose an approach: scenario-based (“an employee loses an unencrypted laptop”) or asset-based (“customer database”). The scenario approach is often more intuitive for an SME.
- Define a simple scale: for example, a 1-to-5 rating for impact and a 1-to-5 rating for likelihood, whose product gives a risk level.
- Set the acceptance threshold: above what level must a risk mandatorily be treated? This threshold is a leadership decision.
- Keep a risk register: a table listing each risk, its owner, impact, likelihood, level, and planned treatment.
- Name risk owners: one accountable person per risk — not “IT” in general, but an identifiable role.
Evidence the auditor will ask for
- The documented risk assessment methodology (criteria, scales, acceptance threshold).
- The completed risk register, with owners, levels, and priorities.
- Proof that the method was actually applied (dates, participants, source data).
- Consistency between the identified risks and the ISMS scope defined in clause 4.
- Traceability into treatment (6.1.3): every significant risk must lead somewhere.
Common pitfalls
- An implicit method: doing the exercise “in your head” without documenting criteria or scales — impossible to reproduce, therefore nonconforming.
- A frozen register: an assessment done once and never revisited, while risks keep evolving.
- Phantom owners: assigning risks to an entire department instead of an accountable person.
- Copying a generic register: reusing a template risk list without grounding it in your real assets and context.
- Confusing assessment and treatment: listing risks (6.1.2) and deciding on measures (6.1.3) are two distinct steps; blending them blurs the logic.
Related requirements
- 6.1.1 General — the general framework for actions to address risks and opportunities.
- 6.1.3 Risk treatment — the next step: deciding what to do about assessed risks and producing the SoA.
- 4.3 ISMS scope — assessment only covers the scope defined here.
- 8.2 Risk assessment (operational) — the recurring implementation of this same process.
- Parent clause: 6.1 Actions to address risks and opportunities
2013 → 2022 mapping
| 2022 version | 2013 version | Nature of change |
|---|---|---|
| 6.1.2 Risk assessment | 6.1.2 Risk assessment | Stable requirement; wording nearly unchanged |
Sources
Frequently asked questions
- Which risk assessment method should I use?
- The standard does not mandate one. You can choose a qualitative or quantitative approach, asset-based (“customer database”) or scenario-based (“an employee loses an unencrypted laptop”) — the scenario approach is often more intuitive for an SME. What matters is that it is defined, documented, and applied consistently and repeatably, so two people reach comparable results.
- Do I need dedicated software?
- No. A well-structured spreadsheet is enough for many SMEs: a register listing each risk, its owner, impact, likelihood, level, and planned treatment. Dedicated tooling becomes useful as the number of risks and assets grows, but it is not required by the standard — what counts is the documented method and the proof that it was actually applied.
- How often should the risk assessment be reviewed?
- The standard requires it to be kept current. In practice, organizations review it at least once a year and after any significant change (new system, new service, major incident, scope change). A frozen register — an assessment done once and never revisited while risks keep evolving — is one of the most common pitfalls raised at audit.
Related pages
ISO 27001 guide · Clause 6
6.1 — Actions to address risks and opportunities
ISO 27001:2022 sub-clause 6.1 requires assessing and treating information security risks and opportunities: how 6.1.1, 6.1.2 and 6.1.3 fit together.
ISO 27001 guide · Clause 6
6.1.1 — General
ISO 27001:2022 sub-clause 6.1.1 sets the general provisions for how risks and opportunities are addressed: the frame that 6.1.2 and 6.1.3 operate inside.
ISO 27001 guide · Clause 6
6.1.3 — Information security risk treatment
ISO 27001:2022 sub-clause 6.1.3 requires a risk treatment process, a risk treatment plan and the Statement of Applicability, plus the supporting evidence.
ISO 27001 guide · Clause 4
4.3 — Determining the scope of the ISMS
ISO 27001:2022 sub-clause 4.3 requires determining the boundaries and applicability of the ISMS to establish its scope, plus the evidence auditors request.
ISO 27001 guide · Clause 8
8.2 — Information security risk assessment
Clause 8.2 requires you to repeat the risk assessment at planned intervals or when a significant change occurs, using the 6.1.2 criteria, and keep the results.
Let's talk about your compliance program.
Last updated: 2026-09-17
