Articles

Information security risk management: from risk to decision

Why information security risks are assessed, which decisions this supports and how the process works in five steps.

A key provider becomes unavailable. Confidential information reaches the wrong person. Important data is altered without anyone noticing. These scenarios have different consequences and call for different responses. Risk management helps identify those differences and make reasoned decisions.

Why does risk management matter?

Time, money and specialist staff are limited. Trying to increase security everywhere at once may direct resources to the wrong places. First, you need to understand which information and business processes matter most and what would happen if their confidentiality, integrity or availability were affected.

The three objectives: confidentiality, integrity and availability

Risk management makes potential harm visible before an incident occurs. It provides a basis for prioritising safeguards according to their significance for the organisation. It cannot promise complete security; its value lies in managing remaining risks consciously.

What decisions does it support?

Risk assessment addresses practical questions: where would an additional safeguard help? Which supplier dependency is critical? What contingency arrangements are needed? Who may decide to accept a residual risk?

A documented process also makes decisions understandable to management, customers and auditors. Assessing and treating information security risks are central to an ISO/IEC 27001 ISMS, but a risk-based approach is useful even without certification plans.

How does the process work?

Five steps in risk management, from setting the context to review
  1. Set the context: Which information, processes and systems are in scope? What criteria will assess consequences and risks? Who owns decisions?
  2. Identify risks: What could go wrong? Consider outages, mistakes, attacks and provider problems, alongside existing safeguards.
  3. Assess and prioritise: How serious would the consequences be, and how plausible is the scenario? Apparently precise figures are not always necessary; consistency and a clear rationale matter.
  4. Decide on treatment: Risks may be reduced, avoided, partly transferred or consciously accepted. Actions need owners and deadlines, and residual risks must be understood.
  5. Review results: New applications, changed processes, incidents and emerging threats can alter earlier assessments. Risk management is a recurring process.

For example, an order-processing system outage affects more than a server. What matters is how long orders can wait, whether a workaround exists and how reliably data can be restored. This view of the business process helps determine appropriate preparation.

What matters is the action that follows

A long risk register alone does not improve security. Risk management becomes useful when it produces clear priorities and workable decisions: What will we do, who will do it, and what risk will remain?

ISO/IEC 27005 and BSI Standard 200-3 provide further methodological guidance. The approach should fit the organisation’s size, processes and decisions.

← Latest articles