ISO 27001 Risk Assessment Form
Systematically identify, evaluate, and manage information security risks in your organization.
Department / Business Unit
*
Please Select
IT
HR
Finance
Operations
Sales/Marketing
Other
Asset Name
*
Asset Owner (Responsible Person)
*
First Name
Last Name
Asset Description
*
Risk Assessment Table
*
Rows
Threat
Vulnerability
Likelihood (1: Rare - 5: Almost Certain)
Impact (1: Negligible - 5: Severe)
Risk Scenario 1
1
2
3
4
5
1
2
3
4
5
Risk Scenario 2
1
2
3
4
5
1
2
3
4
5
Risk Scenario 3
1
2
3
4
5
1
2
3
4
5
Existing Controls (Describe any existing measures mitigating the risk)
*
Risk Level (Based on Likelihood x Impact)
*
Please Select
Low
Medium
High
Risk Treatment Option
*
Accept
Mitigate
Transfer
Avoid
Proposed Action Plan (If Mitigate, Transfer, or Avoid is selected)
Risk Owner (Person responsible for managing this risk)
*
First Name
Last Name
Reviewer's Comments
Submit Assessment
Should be Empty: