Don't Overthink Methodology
Many teams stall on risk assessment because they try to find the "perfect" methodology. ISO 27001 requires a documented, repeatable approach — not a specific one.
A Pragmatic Process
1. Identify Assets
List information assets: databases, applications, documents, people with critical knowledge.
2. Identify Threats & Vulnerabilities
For each asset, ask: what could go wrong? Think about confidentiality, integrity, and availability.
3. Assess Likelihood & Impact
Use a simple scale (e.g., 1–5). Don't agonise over precision — consistency matters more than accuracy.
4. Calculate Risk Level
Likelihood × Impact gives you a risk score. Categorise as Low, Medium, High, Critical.
5. Decide Treatment
For each risk: Accept, Mitigate, Transfer, or Avoid. Document your rationale.