ISO 27001 asks for a risk assessment, a treatment decision on every risk and a Statement of Applicability that follows from them. Keep those as one chain in one file and the controls you select come from the risks, rather than being ticked off a list afterwards and justified later.
Part of the alphaZ ER series of Excel registers, built for listings that grow and need to be sorted and filtered. Supplied in fully editable MS Excel format, with a Google Sheets version included, and all text in Calibri font for improved readability.
The register is set up with:
- Likelihood, Consequence and Treatment drop-downs, with the risk rating calculated automatically
- Annex A controls and risk attributes selected against each risk and summarised back on the risk sheet
- Conditional formatting to highlight higher risks, and filters on the main register
alphaZ documents - tried and tested registers with no junk, jargon or unnecessary columns,
developed over 25 years through practical use in the real world.
Further guidance on information security risk:
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This register is also included in every alphaZ toolkit that covers ISO 27001, from the standalone ISO 27001 Toolkit to the integrated toolkits, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like a hand keeping the register live as threats and systems change, reviewing it at management review, or with your wider information security management system, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Information Security Risks Register Template
An information security risk register template in Microsoft Excel format for recording the risks to the information you hold, scoring them, deciding the treatment for each one and selecting the Annex A controls that address them. A Google Sheets version is included.
ISO 27001:2022 requires an information security risk assessment, a risk treatment process and a Statement of Applicability covering the Annex A controls. This register holds the risk assessment and treatment in one place and links each risk to its controls, so the Statement of Applicability can be driven by the risks rather than written separately. The risk assessment is one of the core records examined during ISO 27001 certification audits.
What's Included in this Information Security Risks Register
The workbook is laid out as separate sheets, each doing one part of the job:
- Risks and Treatment - the main register. Each risk carries its description, known threats and potential consequences, the confidentiality, integrity and availability impact, Likelihood and Consequence drop-downs that set the inherent rating, a summary of current controls, the residual rating, the treatment (accept, reduce, transfer or avoid), the risk owner and comments. The relevant Annex A controls and risk attributes are pulled through automatically from the sheets behind it.
- Risks and SoA Controls - every ISO 27001 Annex A control across the top, grouped as organisational, people, physical and technological, so the controls that apply to each risk can be selected. A count against each control shows at a glance any control not yet linked to a risk.
- Risk Attributes - the ISO 27002 control attributes, such as preventive, detective and corrective, selected against each risk.
- Threat Intelligence - where your threat information comes from, such as incident records, audits and external sources, and anything significant to be considered on the risk register.
- Monitoring - the planned monitoring activity, its rating, who is responsible and how often, so ongoing checks are scheduled rather than remembered.
- Instructions - how to complete the register, the risk rating table, the treatment options and the attribute list behind the drop-downs.
From Risk to Control
The register follows the order the standard sets out. Identify the risk, score it, decide what to do about it, then record which controls carry that decision. Because each risk is linked to its controls, the reason a control is applied can always be traced back to a risk, and a control with no risk behind it shows up on the count row. That is the evidence a Statement of Applicability needs, and it is much harder to produce after the fact.
Who Needs an Information Security Risk Register?
Any organisation implementing or maintaining ISO 27001, or an integrated management system that includes it. It is just as useful without certification in view - customer security questionnaires, Cyber Essentials preparation and supplier due diligence all ask how information security risk is assessed and treated, and a maintained register answers that in one document.
Pairs with the Statement of Applicability
The controls selected in the register feed the F-IMS26 Statement of Applicability, where the decision and justification for every Annex A control is recorded. The F-Q14 Information Assets Matrix sits in front of both, listing the information you hold, where it lives and who owns it.
Blank Template and Sample Data Version
This file is supplied blank, ready for your own risks. A sample data version is included with an alphaZ subscription - the same register populated with a worked set of information security risks, their treatment, the Annex A controls selected and a monitoring plan, as a reference for completing your own.
Would you rather we prepared it for you?
A day of remote support can build this register around your actual systems - your risks scored with a named owner, the treatment decided for each one, the Annex A controls that apply, and the Statement of Applicability completed from the same risk work so the two agree.
Information Security Risk and Treatment Plan