Information Security Risk Assessment for ISO 27001
ISO 27001 Clause 8.2
This sub-clause requires the organisation to perform information security risk assessments at planned intervals or when significant changes occur, retaining documented results.
ISO 27001 Clause 8.2 - Information Security Risk Assessment
Clause 8.2 is the operational repeat of the risk assessment requirements set out in Clause 6.1.2. Clause 6.1.2 establishes the methodology and the initial risk assessment. Clause 8.2 requires the assessment to be repeated regularly so the management system stays current.
What ISO 27001 Clause 8.2 Requires
The organisation must perform information security risk assessments at planned intervals or when significant changes are proposed or occur, taking account of the criteria established under Clause 6.1.2(a) - the risk acceptance criteria and the criteria for performing assessments. Documented information of the results must be retained.
The clause does not specify what 'planned intervals' means. Most organisations review the risk register annually as part of the management review cycle, with smaller updates more frequently as circumstances change.
What Counts as a Significant Change
Significant changes that should trigger a risk reassessment include: new systems or services, changes to existing systems, new suppliers handling sensitive information, changes to the regulatory environment, changes to the threat landscape (a new type of attack becoming common in the sector, for example), changes to the organisation (mergers, acquisitions, restructures), and lessons from incidents - both the organisation's own and significant ones in the wider environment.
The threshold for 'significant' is for the organisation to set. Some changes are obviously significant - moving the entire data estate to a new cloud provider, for example. Others are borderline - adding a new SaaS tool used by a few staff. The methodology should give some guidance on what triggers a formal reassessment versus a note in the change log.
Keeping the Risk Register Current
The most efficient approach is to embed risk reviews into routine activities. The change review form prompts a risk consideration. The supplier review process triggers a re-evaluation of supplier risk. The management review takes a full pass through the register. Incidents trigger a focused review of the related risks.
Treating the risk register as a once-a-year exercise produces a register that is out of date for most of the year. Treating it as a living document fed by the operational processes produces a register that reflects what the organisation actually faces.
The biggest practical benefit of this clause is that it forces the risk register to stay alive. Once it is locked into the change process, the supplier process and the incident process, it updates itself. The annual review then becomes a sense-check rather than a major exercise.
I check the dates in the risk register against the dates of significant changes. If a major new system went live six months ago and the related risks have not been reviewed, the clause is not being met. The reassessments do not have to be heavy. They do have to happen.
Practical Compliance Guidance
The information security risk register is the document that evidences Clause 8.2. The register's review and update history shows that risks are being reassessed at the planned intervals and when changes occur. The change review form ties operational changes back to the risk register.
The documents below support ongoing risk assessment and reassessment for an ISO 27001 management system.
| alphaZ document | How to use it |
|---|---|
| ISO 27001 Toolkit | Complete documentation set for ISO 27001:2022 including the risk register, change review form and management review template. |
| ER15 Information Security Risks Register | Risk register with built-in tracking of review dates and update history, used to evidence ongoing risk reassessment. |
| F-Q23 Change Review Form | Change review form that prompts a risk consideration as part of any significant operational change. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The same UK legislation that applies to Clause 6.1.2 applies here, with the additional point that legislative changes are themselves a trigger for risk reassessment under Clause 8.2.
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Network and Information Systems Regulations 2018
