Comparison of risk analysis results with established risk management criteria

Comparison of risk analysis results with established risk management criteria

Risk evaluation is where mathematical analysis and categorical assessment meet corporate governance. According to ISO/IEC 27005, risk evaluation is the formal process of comparing the results of the risk analysis against the organisation's predefined risk criteria to determine whether the risk, or its overall magnitude, is acceptable or tolerable. This comparison helps decide whether an organisation should invest capital and human resources in risk treatment or retain the risk within normal operational boundaries.

The standard strongly stipulates that risk criteria must be established during the initial context establishment phase and must encompass both risk assessment criteria (defining how consequences and likelihood are measured) and risk acceptance criteria (the absolute thresholds that determine acceptability). These criteria are not arbitrary technical metrics; they must be derived directly from the organisation's overarching risk appetite, established by the Board of Directors and dictating the amount and type of risk the enterprise is willing to pursue or retain to achieve its strategic and financial objectives.

Risk acceptance criteria may be absolute or conditional. Absolute criteria dictate zero tolerance for specific outcomes; for example, a policy stating that any risk that results in a loss of human life or a failure to comply with critical regulations (such as PCI-DSS or HIPAA) is unequivocally unacceptable. Conditional criteria allow for nuance, such as temporarily accepting a high technical risk because a mitigating capital expenditure project is already funded and in the deployment pipeline.

A pervasive challenge in the cybersecurity industry is the frequent, dangerous misalignment between the technical risk analysis results generated by security practitioners and the established risk management criteria understood by the executive board. Often, security teams present risk results using strictly technical severity scores, such as Common Vulnerability Scoring System (CVSS) rankings, which do not map cleanly to the organisation's financial or strategic risk acceptance thresholds. If the enterprise risk criteria dictate that any risk causing more than a 2% drop in quarterly revenue is unacceptable, a technical report highlighting "15 Critical SQL Injection vulnerabilities" fails to provide the necessary comparative business context. Furthermore, organisations operating in highly regulated industries face a continuously shifting regulatory baseline, which severely complicates the establishment of stable risk criteria.

The introduction of stringent data sovereignty laws, AI governance regulations (such as the EU AI Act), and enhanced supply chain oversight directives (such as the EU NIS2 Directive) means that a risk considered perfectly acceptable in one fiscal year may drastically exceed the risk acceptance criteria in the next due to massive increases in potential regulatory penalties. Consequently, maintaining static risk criteria is no longer a viable governance strategy; organisations must continuously and dynamically calibrate their risk acceptance thresholds in response to geopolitical shifts, macroeconomic volatility, and rapid legislative developments.

Advanced Risk Management

Buy nowLearn more
  • Course Motivation

0.0 Shifting from technical execution to strategic risk management.

  • The Strategic Imperative of the Security Function
  • IBM - Motivation for Risk Analysis in CyberSecurity (11 min)
  • Google - Security Frameworks (30 min)
  • Introduction: The Evolution of Security Management

1. Introduction to ISO/IEC 27005 and information security risk management

  • Introduction: The Evolution of Risk Management Standardisation
  • International Standardisation: ISO 31000 versus ISO 27005
  • The ISO Risk Management and other frameworks
  • The Psychology of Risk Perception and Decision-Making
  • The ISO 31000 Architecture: Principles, Framework, and Process
  • Review of Risk Assessment Methodologies (IEC 31010)
  • Scope, Context, and Criteria
  • Leadership, Governance, and Corporate Commitment
  • Quiz01 - Risk Management [Day01]

2. Information Security Risk Identification, Assessment, and Treatment (ISO/IEC 27005)

Delayed 1 day

  • Identification and description of information security risks
  • Identification of risk owners
  • Assessment of potential consequences
  • Determination of risk levels
  • Comparison of risk analysis results with established risk management criteria
  • Risk prioritization
  • Determination of required controls for risk treatment
  • Risk treatment plan
  • Quiz02 - Risk Identification, Assessment and Treatment [day2]

3 - Risk Acceptance, Communication, Monitoring and Review

Delayed 2 days

  • Key Take aways (Module 01 - Module 02)
  • Quiz03 - Recap - Session 1 & 2
  • Communication and Consultation of Results
  • Documentation of the Risk Analysis Process
  • Documentation of Results
  • Monitoring of Risk-Generating Factors
  • Deep Dive: Navigating Complexity with ISO/TS 31050 and the Risk Intelligence Cycle
  • Future-Looking Challenges for Risk Management and ISO/IEC 27005

4 - Risk Assessment Methodologies

Delayed 3 days

  • The Methodological Shift: Transcending Traditional Frameworks
  • Technique 1: STRIDE for Cloud and PaaS Architectures
  • Technique 2: Subjective Evaluation of Opaque AI Risks
  • FMEA, Red Teaming, and Risk Register Integration
  • Risk Monitoring Processes
  • Part B: Procedure to Execute an FMEA Analysis

05 - ISO 27005 Risk Assessment Using FMEA

Delayed 4 days

  • Process Overview - Lab: AI and Cloud Services
  • Quiz - Simulation exam
  • Quiz - summary