ISO 27001 Risk Assessment: From Assets to Treatment
A practical way to keep risk identification, treatment decisions and control implementation connected.
Start with what the organization needs to protect
A useful assessment begins with the ISMS scope and the information, processes, services and supporting technology that matter to that scope. The objective is not to create an exhaustive inventory of everything the company owns; it is to establish enough context to identify meaningful information-security risks.
Make the risk method repeatable
Define how likelihood and impact are assessed, what risk levels mean, who can accept risk and when escalation is required. A repeatable method makes risk decisions comparable over time and reduces arguments about why two similar risks received different treatment.
Connect risks to treatments
Each material risk should have a treatment decision, owner and target state. Treatment may involve reducing, avoiding, transferring or accepting risk. The important part is that the decision is explicit and can be traced to the organization's criteria.
Then connect treatment to controls
Controls should be selected because they help address identified risks and applicable requirements. This creates a useful chain: risk → treatment → control → owner → operating evidence. When those links are missing, the risk register and control set tend to become separate administrative exercises.
Common failure modes
- Large risk registers with no meaningful ownership.
- Risk scores that change without documented criteria.
- Treatments that say “implement a control” without defining the target state.
- Controls listed in the SoA that cannot be linked back to the risk or applicability rationale.
- Accepted risks with no accountable approval or review mechanism.
A practical review question
Pick one material risk and follow it through the system. Can you find the assessment basis, treatment decision, responsible owner, related controls and evidence that the treatment operates? If not, the process likely needs strengthening before an audit.
Ready to strengthen your ISMS?
Explore how BlueLock approaches ISO 27001 implementation and readiness.