Communication and Consultation of Results

Communication and Consultation of Results

Effective risk management cannot occur in an operational vacuum. ISO/IEC 27005:2022 emphasises that communication and consultation constitute a continuous, iterative process for sharing information and engaging in dialogue with internal and external interested parties about the nature, significance, and treatment of information security risks. The primary objective is to achieve a documented agreement on risk management by establishing bidirectional communication channels among risk owners, top management, and personnel responsible for implementing ISMS controls.

Risk ownership is frequently a point of friction within modern enterprises. Individuals may be reluctant to acknowledge accountability, or ownership may be deliberately obfuscated in highly decentralised, matrixed organisations. Therefore, a formalised communication procedure is vital to definitively inform personnel of their risk ownership status and the specific accountabilities tied to that designation. Risk owners must understand the risk scenarios, approve the risk treatment plans, and make the final, informed executive decision on whether to accept any residual risk after controls are implemented.

Furthermore, perceptions of risk vary drastically across an organisation due to differences in assumptions, operational needs, and the cognitive biases discussed previously. Communication must be tailored to address these varying perceptions, ensuring that stakeholders understand the underlying rationale behind risk acceptance decisions and the calculation of risk criteria. By involving stakeholders early in the risk assessment design phase and as methodologies are selected, organisations increase the likelihood that findings will be accepted and treatment plans supported. Interested parties are fundamentally less likely to question the outcomes of processes that they have helped design, effectively building executive commitment and securing necessary resources.

However, the distribution of risk intelligence must be carefully managed. Since risk assessments specify the vulnerabilities and potential failure points of an organisation's critical infrastructure, communication should be strictly controlled on a "need-to-know" basis. The aim is to prevent sensitive weaknesses from being disclosed to internal personnel who do not need the information or to external entities, thereby unintentionally increasing the risk of exploitation. Organisations are advised to establish dedicated risk committees to facilitate secure discussion of prioritisation and to develop specialised communication plans for both routine operations and crisis management.

Advanced Risk Management

Buy nowLearn more
  • Course Motivation

0.0 Shifting from technical execution to strategic risk management.

  • The Strategic Imperative of the Security Function
  • IBM - Motivation for Risk Analysis in CyberSecurity (11 min)
  • Google - Security Frameworks (30 min)
  • Introduction: The Evolution of Security Management

1. Introduction to ISO/IEC 27005 and information security risk management

  • Introduction: The Evolution of Risk Management Standardisation
  • International Standardisation: ISO 31000 versus ISO 27005
  • The ISO Risk Management and other frameworks
  • The Psychology of Risk Perception and Decision-Making
  • The ISO 31000 Architecture: Principles, Framework, and Process
  • Review of Risk Assessment Methodologies (IEC 31010)
  • Scope, Context, and Criteria
  • Leadership, Governance, and Corporate Commitment
  • Quiz01 - Risk Management [Day01]

2. Information Security Risk Identification, Assessment, and Treatment (ISO/IEC 27005)

Delayed 1 day

  • Identification and description of information security risks
  • Identification of risk owners
  • Assessment of potential consequences
  • Determination of risk levels
  • Comparison of risk analysis results with established risk management criteria
  • Risk prioritization
  • Determination of required controls for risk treatment
  • Risk treatment plan
  • Quiz02 - Risk Identification, Assessment and Treatment [day2]

3 - Risk Acceptance, Communication, Monitoring and Review

Delayed 2 days

  • Key Take aways (Module 01 - Module 02)
  • Quiz03 - Recap - Session 1 & 2
  • Communication and Consultation of Results
  • Documentation of the Risk Analysis Process
  • Documentation of Results
  • Monitoring of Risk-Generating Factors
  • Deep Dive: Navigating Complexity with ISO/TS 31050 and the Risk Intelligence Cycle
  • Future-Looking Challenges for Risk Management and ISO/IEC 27005

4 - Risk Assessment Methodologies

Delayed 3 days

  • The Methodological Shift: Transcending Traditional Frameworks
  • Technique 1: STRIDE for Cloud and PaaS Architectures
  • Technique 2: Subjective Evaluation of Opaque AI Risks
  • FMEA, Red Teaming, and Risk Register Integration
  • Risk Monitoring Processes
  • Part B: Procedure to Execute an FMEA Analysis

05 - ISO 27005 Risk Assessment Using FMEA

Delayed 4 days

  • Process Overview - Lab: AI and Cloud Services
  • Quiz - Simulation exam
  • Quiz - summary