Risk Assessment Methodology Guide
Comprehensive guidance for conducting information security risk assessments per ISO 27001 Clause 6.1.2.
Table of Contents
Risk Assessment Process
ISO 27001 Requirements (Clause 6.1.2)
The organization shall:
- Define risk assessment process
- Establish risk criteria (acceptance, assessment)
- Identify information security risks
- Analyze and evaluate risks
- Ensure repeatable and consistent results
Process Overview
1. Context → 2. Asset ID → 3. Threat ID → 4. Vuln ID → 5. Risk Calc → 6. Treatment
↑ |
└──────────────────── Review & Update ←───────────────────────────────┘
Asset Identification
Asset Categories
| Category |
Examples |
Typical Classification |
| Information |
Patient records, source code, contracts |
Confidential-Critical |
| Software |
EHR systems, databases, custom apps |
High-Critical |
| Hardware |
Servers, medical devices, network gear |
High |
| Services |
Cloud hosting, backup, email |
High |
| People |
Admin accounts, key personnel |
Critical |
| Intangibles |
Reputation, intellectual property |
High |
Classification Scheme
| Level |
Definition |
Impact if Compromised |
| Critical |
Business-critical, regulated data |
Severe - regulatory fines, safety risk |
| High |
Important business data |
Significant - major disruption |
| Medium |
Internal business data |
Moderate - operational impact |
| Low |
Non-sensitive data |
Minor - limited impact |
| Public |
Intended for public release |
Minimal - no impact |
Asset Inventory Template
| ID |
Asset Name |
Type |
Owner |
Location |
Classification |
Value |
| A001 |
Patient DB |
Information |
DBA Lead |
AWS RDS |
Critical |
$5M |
| A002 |
EHR App |
Software |
App Team |
AWS ECS |
Critical |
$2M |
| A003 |
Admin Creds |
Access |
Security |
Vault |
Critical |
N/A |
Threat Analysis
Healthcare Threat Landscape
| Threat |
Likelihood |
Target Assets |
Motivation |
| Ransomware |
High |
All systems |
Financial |
| Data breach |
High |
Patient data |
Financial/Competitive |
| Phishing |
Very High |
User accounts |
Access |
| Insider threat |
Medium |
Sensitive data |
Various |
| DDoS |
Medium |
Public services |
Disruption |
| Supply chain |
Medium |
Third-party systems |
Access |
Threat Modeling Approaches
STRIDE Model:
- Spoofing identity
- Tampering with data
- Repudiation
- Information disclosure
- Denial of service
- Elevation of privilege
Threat Actor Categories:
| Actor |
Capability |
Motivation |
Typical Targets |
| Nation-state |
Very High |
Espionage, disruption |
Critical infrastructure |
| Organized crime |
High |
Financial gain |
Healthcare, finance |
| Hacktivists |
Medium |
Ideology |
Public-facing systems |
| Insiders |
Varies |
Financial, revenge |
Sensitive data |
| Script kiddies |
Low |
Notoriety |
Unpatched systems |
Vulnerability Assessment
Vulnerability Categories
| Category |
Examples |
Detection Method |
| Technical |
Unpatched software, weak configs |
Vulnerability scans |
| Process |
Missing procedures, gaps |
Process audits |
| People |
Lack of training, social engineering |
Phishing tests |
| Physical |
Inadequate access controls |
Physical audits |
Vulnerability Scoring (CVSS Alignment)
| Score Range |
Severity |
Example |
| 9.0-10.0 |
Critical |
RCE without authentication |
| 7.0-8.9 |
High |
Authentication bypass |
| 4.0-6.9 |
Medium |
Information disclosure |
| 0.1-3.9 |
Low |
Minor configuration issue |
Vulnerability Sources
- Automated Scans: Nessus, Qualys, OpenVAS
- Penetration Testing: Annual third-party tests
- Code Analysis: SAST/DAST tools
- Configuration Audits: CIS benchmarks
- Threat Intelligence: CVE feeds, vendor advisories
Risk Calculation
Risk Formula
Risk = Likelihood × Impact
Likelihood Scale (1-5)
| Score |
Likelihood |
Definition |
| 5 |
Almost Certain |
Expected to occur multiple times per year |
| 4 |
Likely |
Expected to occur at least once per year |
| 3 |
Possible |
Could occur within 2-3 years |
| 2 |
Unlikely |
Could occur within 5 years |
| 1 |
Rare |
Unlikely to occur |
Impact Scale (1-5)
| Score |
Impact |
Financial |
Operational |
Reputational |
| 5 |
Catastrophic |
>$10M |
Total shutdown |
International news |
| 4 |
Major |
$1M-$10M |
Major disruption |
National news |
| 3 |
Moderate |
$100K-$1M |
Significant impact |
Local news |
| 2 |
Minor |
$10K-$100K |
Minor disruption |
Complaints |
| 1 |
Negligible |
<$10K |
Minimal impact |
Internal only |
Risk Matrix
|
Impact 1 |
Impact 2 |
Impact 3 |
Impact 4 |
Impact 5 |
| L5 |
5 (Low) |
10 (Med) |
15 (High) |
20 (Crit) |
25 (Crit) |
| L4 |
4 (Low) |
8 (Med) |
12 (Med) |
16 (High) |
20 (Crit) |
| L3 |
3 (Min) |
6 (Low) |
9 (Med) |
12 (Med) |
15 (High) |
| L2 |
2 (Min) |
4 (Low) |
6 (Low) |
8 (Med) |
10 (Med) |
| L1 |
1 (Min) |
2 (Min) |
3 (Min) |
4 (Low) |
5 (Low) |
Risk Levels
| Level |
Score Range |
Action Required |
| Critical |
20-25 |
Immediate action, escalate to management |
| High |
15-19 |
Treatment plan within 30 days |
| Medium |
10-14 |
Treatment plan within 90 days |
| Low |
5-9 |
Accept or implement low-cost controls |
| Minimal |
1-4 |
Accept risk, document decision |
Risk Treatment
Treatment Options (ISO 27001)
| Option |
Description |
When to Use |
| Modify |
Implement controls to reduce risk |
Most risks |
| Avoid |
Eliminate the risk source |
Unacceptable risks |
| Share |
Transfer via insurance/outsourcing |
High financial impact |
| Retain |
Accept the risk |
Low risks, cost-prohibitive controls |
Control Selection Criteria
- Effectiveness: Reduces likelihood or impact
- Cost: Implementation and maintenance costs
- Feasibility: Technical and operational viability
- Compliance: Meets regulatory requirements
- Integration: Works with existing controls
Residual Risk
After implementing controls:
Residual Risk = Inherent Risk × (1 - Control Effectiveness)
| Control Effectiveness |
Residual Risk Factor |
| 90%+ |
Very Low (0.1×) |
| 70-89% |
Low (0.2-0.3×) |
| 50-69% |
Moderate (0.4-0.5×) |
| <50% |
Limited reduction |
Templates and Tools
Risk Register Template
| Risk ID |
Asset |
Threat |
Vulnerability |
L |
I |
Inherent |
Control |
Residual |
Owner |
Status |
| R001 |
Patient DB |
Data breach |
Weak encryption |
4 |
5 |
20 |
AES-256 |
8 |
DBA |
Open |
| R002 |
Admin access |
Credential theft |
No MFA |
5 |
5 |
25 |
MFA |
5 |
Security |
Closed |
Risk Assessment Report Sections
Executive Summary
- Key findings
- Critical/high risks count
- Overall risk posture
Methodology
- Assessment scope
- Criteria used
- Limitations
Asset Summary
- Asset inventory
- Classification distribution
Risk Findings
- Risk register
- Heat map visualization
- Trend analysis
Recommendations
- Priority treatments
- Timeline and resources
- Residual risk projection
Appendices
- Detailed asset list
- Threat catalog
- Control mapping
1---2name: risk-assessment-methodology-guide3description: Comprehensive guidance for conducting information security risk assessments per ISO 27001 Clause 6.1.2.4---5# Risk Assessment Methodology Guide67Comprehensive guidance for conducting information security risk assessments per ISO 27001 Clause 6.1.2.89---1011## Table of Contents1213- [Risk Assessment Process](#risk-assessment-process)14- [Asset Identification](#asset-identification)15- [Threat Analysis](#threat-analysis)16- [Vulnerability Assessment](#vulnerability-assessment)17- [Risk Calculation](#risk-calculation)18- [Risk Treatment](#risk-treatment)19- [Templates and Tools](#templates-and-tools)2021---2223## Risk Assessment Process2425### ISO 27001 Requirements (Clause 6.1.2)2627The organization shall:281. Define risk assessment process292. Establish risk criteria (acceptance, assessment)303. Identify information security risks314. Analyze and evaluate risks325. Ensure repeatable and consistent results3334### Process Overview3536```371. Context → 2. Asset ID → 3. Threat ID → 4. Vuln ID → 5. Risk Calc → 6. Treatment38 ↑ |39 └──────────────────── Review & Update ←───────────────────────────────┘40```4142---4344## Asset Identification4546### Asset Categories4748| Category | Examples | Typical Classification |49|----------|----------|----------------------|50| Information | Patient records, source code, contracts | Confidential-Critical |51| Software | EHR systems, databases, custom apps | High-Critical |52| Hardware | Servers, medical devices, network gear | High |53| Services | Cloud hosting, backup, email | High |54| People | Admin accounts, key personnel | Critical |55| Intangibles | Reputation, intellectual property | High |5657### Classification Scheme5859| Level | Definition | Impact if Compromised |60|-------|------------|----------------------|61| Critical | Business-critical, regulated data | Severe - regulatory fines, safety risk |62| High | Important business data | Significant - major disruption |63| Medium | Internal business data | Moderate - operational impact |64| Low | Non-sensitive data | Minor - limited impact |65| Public | Intended for public release | Minimal - no impact |6667### Asset Inventory Template6869| ID | Asset Name | Type | Owner | Location | Classification | Value |70|----|------------|------|-------|----------|----------------|-------|71| A001 | Patient DB | Information | DBA Lead | AWS RDS | Critical | $5M |72| A002 | EHR App | Software | App Team | AWS ECS | Critical | $2M |73| A003 | Admin Creds | Access | Security | Vault | Critical | N/A |7475---7677## Threat Analysis7879### Healthcare Threat Landscape8081| Threat | Likelihood | Target Assets | Motivation |82|--------|------------|---------------|------------|83| Ransomware | High | All systems | Financial |84| Data breach | High | Patient data | Financial/Competitive |85| Phishing | Very High | User accounts | Access |86| Insider threat | Medium | Sensitive data | Various |87| DDoS | Medium | Public services | Disruption |88| Supply chain | Medium | Third-party systems | Access |8990### Threat Modeling Approaches9192**STRIDE Model:**93- **S**poofing identity94- **T**ampering with data95- **R**epudiation96- **I**nformation disclosure97- **D**enial of service98- **E**levation of privilege99100**Threat Actor Categories:**101102| Actor | Capability | Motivation | Typical Targets |103|-------|-----------|------------|-----------------|104| Nation-state | Very High | Espionage, disruption | Critical infrastructure |105| Organized crime | High | Financial gain | Healthcare, finance |106| Hacktivists | Medium | Ideology | Public-facing systems |107| Insiders | Varies | Financial, revenge | Sensitive data |108| Script kiddies | Low | Notoriety | Unpatched systems |109110---111112## Vulnerability Assessment113114### Vulnerability Categories115116| Category | Examples | Detection Method |117|----------|----------|------------------|118| Technical | Unpatched software, weak configs | Vulnerability scans |119| Process | Missing procedures, gaps | Process audits |120| People | Lack of training, social engineering | Phishing tests |121| Physical | Inadequate access controls | Physical audits |122123### Vulnerability Scoring (CVSS Alignment)124125| Score Range | Severity | Example |126|-------------|----------|---------|127| 9.0-10.0 | Critical | RCE without authentication |128| 7.0-8.9 | High | Authentication bypass |129| 4.0-6.9 | Medium | Information disclosure |130| 0.1-3.9 | Low | Minor configuration issue |131132### Vulnerability Sources1331341. **Automated Scans:** Nessus, Qualys, OpenVAS1352. **Penetration Testing:** Annual third-party tests1363. **Code Analysis:** SAST/DAST tools1374. **Configuration Audits:** CIS benchmarks1385. **Threat Intelligence:** CVE feeds, vendor advisories139140---141142## Risk Calculation143144### Risk Formula145146```147Risk = Likelihood × Impact148```149150### Likelihood Scale (1-5)151152| Score | Likelihood | Definition |153|-------|-----------|------------|154| 5 | Almost Certain | Expected to occur multiple times per year |155| 4 | Likely | Expected to occur at least once per year |156| 3 | Possible | Could occur within 2-3 years |157| 2 | Unlikely | Could occur within 5 years |158| 1 | Rare | Unlikely to occur |159160### Impact Scale (1-5)161162| Score | Impact | Financial | Operational | Reputational |163|-------|--------|-----------|-------------|--------------|164| 5 | Catastrophic | >$10M | Total shutdown | International news |165| 4 | Major | $1M-$10M | Major disruption | National news |166| 3 | Moderate | $100K-$1M | Significant impact | Local news |167| 2 | Minor | $10K-$100K | Minor disruption | Complaints |168| 1 | Negligible | <$10K | Minimal impact | Internal only |169170### Risk Matrix171172| | Impact 1 | Impact 2 | Impact 3 | Impact 4 | Impact 5 |173|-----|----------|----------|----------|----------|----------|174| **L5** | 5 (Low) | 10 (Med) | 15 (High) | 20 (Crit) | 25 (Crit) |175| **L4** | 4 (Low) | 8 (Med) | 12 (Med) | 16 (High) | 20 (Crit) |176| **L3** | 3 (Min) | 6 (Low) | 9 (Med) | 12 (Med) | 15 (High) |177| **L2** | 2 (Min) | 4 (Low) | 6 (Low) | 8 (Med) | 10 (Med) |178| **L1** | 1 (Min) | 2 (Min) | 3 (Min) | 4 (Low) | 5 (Low) |179180### Risk Levels181182| Level | Score Range | Action Required |183|-------|-------------|-----------------|184| Critical | 20-25 | Immediate action, escalate to management |185| High | 15-19 | Treatment plan within 30 days |186| Medium | 10-14 | Treatment plan within 90 days |187| Low | 5-9 | Accept or implement low-cost controls |188| Minimal | 1-4 | Accept risk, document decision |189190---191192## Risk Treatment193194### Treatment Options (ISO 27001)195196| Option | Description | When to Use |197|--------|-------------|-------------|198| Modify | Implement controls to reduce risk | Most risks |199| Avoid | Eliminate the risk source | Unacceptable risks |200| Share | Transfer via insurance/outsourcing | High financial impact |201| Retain | Accept the risk | Low risks, cost-prohibitive controls |202203### Control Selection Criteria2042051. **Effectiveness:** Reduces likelihood or impact2062. **Cost:** Implementation and maintenance costs2073. **Feasibility:** Technical and operational viability2084. **Compliance:** Meets regulatory requirements2095. **Integration:** Works with existing controls210211### Residual Risk212213After implementing controls:214215```216Residual Risk = Inherent Risk × (1 - Control Effectiveness)217```218219| Control Effectiveness | Residual Risk Factor |220|----------------------|---------------------|221| 90%+ | Very Low (0.1×) |222| 70-89% | Low (0.2-0.3×) |223| 50-69% | Moderate (0.4-0.5×) |224| <50% | Limited reduction |225226---227228## Templates and Tools229230### Risk Register Template231232| Risk ID | Asset | Threat | Vulnerability | L | I | Inherent | Control | Residual | Owner | Status |233|---------|-------|--------|---------------|---|---|----------|---------|----------|-------|--------|234| R001 | Patient DB | Data breach | Weak encryption | 4 | 5 | 20 | AES-256 | 8 | DBA | Open |235| R002 | Admin access | Credential theft | No MFA | 5 | 5 | 25 | MFA | 5 | Security | Closed |236237### Risk Assessment Report Sections2382391. **Executive Summary**240 - Key findings241 - Critical/high risks count242 - Overall risk posture2432442. **Methodology**245 - Assessment scope246 - Criteria used247 - Limitations2482493. **Asset Summary**250 - Asset inventory251 - Classification distribution2522534. **Risk Findings**254 - Risk register255 - Heat map visualization256 - Trend analysis2572585. **Recommendations**259 - Priority treatments260 - Timeline and resources261 - Residual risk projection2622636. **Appendices**264 - Detailed asset list265 - Threat catalog266 - Control mapping