Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Information Security Risk Assessment (ISO 27001)

Score asset risks on your own scale, with heat maps before and after and a treatment plan.

Security No upload Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: the counts and the watermarked heat maps for all your risks, and the first rows (up to 10) of the register, the treatment plan and the findings.
  • Locked until you unlock it: download.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Heat maps

Assessment and method

Scale

Changing the scale resets the level names and descriptions to that size’s defaults; ratings above the new top level are lowered to it.

Level of risk

Level names and the highest score of each band (scores run from 1 to 25).

Likelihood levels

    Impact levels

      Assets

      Information, systems, devices, suppliers, people and premises the risks are about.

        Threats and vulnerabilities

        Starting lists to choose from: rename, add or remove entries. Threat types follow NIST SP 800-30.

        Threats

          Vulnerabilities

            Risks

            Add a risk for each thing that could go wrong: an asset, the threat to it and the weakness the threat would use.

              Heat maps

              Before treatment
              After treatment

                Findings

                    Risk register

                    Risks in order of inherent risk, highest first
                    RiskAssetThreat and vulnerabilityInherentTreatmentControlsResidualOwnerStatus

                    Risk treatment plan

                    Risks being modified, avoided or shared, highest first
                    RiskTreatmentControls and actionsOwnerDueStatusResidual

                    Annex A controls

                      Next steps

                      For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.

                      About the Information Security Risk Assessment (ISO 27001)

                      ISO/IEC 27001:2022 clause 6.1.2 asks you to identify the risks to the confidentiality, integrity and availability of your information, give each an owner, analyse and evaluate them against criteria you set, and choose how to treat them. This tool runs that assessment the way NIST SP 800-30 Rev. 1 describes it: an asset register, threats and vulnerabilities from editable libraries, likelihood and impact on a 3 × 3, 4 × 4 or 5 × 5 scale whose levels you name and describe, and the level of risk from likelihood × impact in bands you set, or from the NIST matrix.

                      For each risk you record how it is treated, the Annex A controls chosen, the actions, the residual rating and the owner. You get heat maps before and after treatment, a risk register in order of risk, the risk treatment plan, findings against your acceptance criteria, and a control list you can send straight to the Statement of Applicability Generator. Unlike a project risk register, it is organised around information assets and security controls.

                      The free preview scores every risk and shows the heat maps watermarked and the first rows of each table; the Excel and PDF files need a Premium pass. Nothing you enter is uploaded.

                      How to use it

                      1. Under Assessment and method, choose the scale (3 × 3 to 5 × 5), name and describe each likelihood and impact level, set the bands (or choose the NIST SP 800-30 matrix on a 5 × 5 scale) and the level up to which owners may retain a risk.
                      2. List the assets: information, applications, devices, suppliers, people and premises, each with an owner. Adjust the starting lists of threats and vulnerabilities if you need to.
                      3. Add a risk for each scenario: the asset, the threat and the vulnerability, then the likelihood and impact before treatment.
                      4. Choose the treatment. For “modify”, pick the Annex A controls and describe the actions, then rate the likelihood and impact after treatment; name the owner and a due date.
                      5. Read the heat maps and the Findings (risks still above the acceptance level, retained without a record, without owner or due date) and use Send the controls to the Statement of Applicability.
                      6. With a Premium pass, download the risk register, treatment plan and heat maps as Excel or the full report as PDF; without one, the free preview shows the counts, the watermarked heat maps and the first rows. Save answers keeps a file of the assessment with or without a pass.

                      Examples

                      The example assessment
                      Input
                      Example: a software company with six assets and nine risks on a 5 × 5 scale; owners may retain risks up to Medium
                      Result
                      Before treatment: 1 Critical, 3 High, 4 Medium (one risk not rated yet). After treatment: 1 High, 5 Medium, 2 Low. Findings: one risk not rated, the administrator-account risk still High after treatment, and one treatment without a due date.

                      Press Example on the page.

                      Scoring on the NIST matrix
                      Input
                      5 × 5 scale, NIST SP 800-30 matrix: likelihood Low (2), impact Very high (5)
                      Result
                      Level of risk: Moderate (Table I-2), where likelihood × impact would give 10.

                      Common uses

                      • The risk assessment of a first ISO/IEC 27001 certification.
                      • The yearly review of the risk register before a surveillance audit or a SOC 2 examination.
                      • Showing management where the biggest risks are, before and after the planned controls.
                      • Turning risk decisions into the control list of the Statement of Applicability.

                      How the level of risk is worked out

                      • Likelihood × impact, in bands: the score runs from 1 to 9, 16 or 25 with the scale. The suggested bands for a 5 × 5 scale are Low up to 4, Medium up to 9, High up to 16 and Critical above; change the names and limits to your own risk criteria.
                      • The NIST SP 800-30 matrix (5 × 5): Table I-2 of NIST SP 800-30 Rev. 1 gives the level of risk for each combination of likelihood and impact, from very low to very high. It is not symmetrical: a very likely event with moderate impact is a moderate risk, a moderately likely one with very high impact a high risk.

                      The default level descriptions are written in plain words; for errors and failures they give the yearly frequencies NIST uses as a guide (from less than once in ten years to more than a hundred times a year).

                      Treatment options and acceptance

                      • Modify: reduce the likelihood or impact with controls; rate the residual risk after them.
                      • Retain: accept the risk as it is. Within your acceptance level the owner may decide; above it, the tool asks for a recorded decision.
                      • Avoid: stop or change the activity that causes the risk.
                      • Share: transfer part of it, for example with insurance or a supplier contract.

                      Where no residual rating is entered, the residual risk is taken to be the same as the inherent one and marked with an asterisk in the outputs.

                      From risks to the Statement of Applicability

                      Every control you choose for a risk is collected with the risks it treats. Send the controls to the Statement of Applicability opens the Statement of Applicability Generator in a new tab, so this assessment stays open, and offers to include those controls with their risk IDs; Save the control list gives you the same as a file. The risk policy text itself can come from the Information Security Policy Generator.

                      Sources

                      Limitations

                      • A working tool for your ISMS, not professional advice: the ratings and the treatment decisions are yours and your risk owners’.
                      • Qualitative ratings: there is no money estimate (annual loss expectancy) or Monte Carlo simulation.
                      • The starting threats and vulnerabilities are a common baseline, not a complete catalogue for your sector; add what applies to you.
                      • One asset per risk: for a scenario that touches several assets, add a risk per asset or name the main one.

                      Privacy

                      Your assessment stays in this browser and is never uploaded: it describes your weaknesses, so it should not leave your hands. Keep this assessment in this browser is off unless you switch it on; Save answers gives you a file to keep instead.

                      Frequently asked questions

                      What do I get without a pass?

                      Without a pass, Information Security Risk Assessment (ISO 27001) shows the counts and the watermarked heat maps for all your risks, and the first rows (up to 10) of the register, the treatment plan and the findings. Until you unlock it, the result can’t be downloaded. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

                      Which scale should we use?

                      A 5 × 5 scale separates risks best and is the most common; a 3 × 3 scale is quicker for a small organisation and still meets the standard, which leaves the method to you. What matters is that the levels are described clearly enough for two people to rate the same risk the same way, and that you use the same scale at the next review.

                      What is the difference between inherent and residual risk?

                      Inherent risk is the rating before the treatment you plan; residual risk is the rating once that treatment is in place. Many organisations rate the inherent risk with the controls they already have, and the residual risk with the planned ones. Whichever you choose, say so in your method and keep to it.

                      Does this replace ISO 27005 or a risk management standard?

                      No. It is a practical way to record an assessment that follows ISO/IEC 27001 clause 6.1.2 and NIST SP 800-30. ISO/IEC 27005 gives guidance on information security risk management in more depth, and your method may follow it as well.

                      Why are the levels hidden on the risk cards in the free preview?

                      The computed levels are part of the result. The free preview scores every risk for the counts and the heat maps, and shows the first rows of the register, the treatment plan and the findings; a Premium pass shows everything and unlocks the Excel and PDF files.

                      Where is my assessment kept?

                      Only in this page while it is open, unless you switch on Keep this assessment in this browser or save the answers file. Nothing is sent to a server.

                      Quick answers and tool search

                      Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.