workflow

ISMS Risk Assessment & Treatment Cycle

Perform an ISO 27005 information security risk assessment and treatment cycle for a defined ISMS scope. The recurring cycle instance attaches to the existing Process item (process_type=security_process) that represents the ISMS scope — enrich that item, never create a duplicate; the risk register it produces is the set of Risk items the run creates and updates. The cycle: establish context and risk criteria, identify information security risks, analyze and evaluate them against the criteria, select treatment options, draft the risk treatment plan, obtain residual-risk acceptance, and retain the documented information. In scope: risk identification through treatment planning and residual-risk acceptance for the ISMS boundary. Out of scope: the Statement of Applicability control-applicability determination and control operating-effectiveness testing, which are handled downstream. This workflow has no upstream workflow — its boundary and inventory are initial inputs: the in-scope business processes are existing Process items, while the asset/information inventory and risk criteria are uploaded documents (no native Asset type). It produces the named deliverables — the current risk register (Risk items), the Risk Treatment Plan (RTP), and the SoA inputs — handed off to the ISO 27001 SoA Review & Controls Assessment workflow.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • risk-management
domains
  • controls
standards
  • iso-27001
  • iso-31000
sourceTemplateId
workflow-library:controls-isms-risk-assessment-treatment
releaseId
sha256:d28392c2f1ee0bffec0f16bf8935ffe4a883954a3dbec02d0f981ced07f5dcee
canonicalUrl
https://workflow-library.com/all/?w=controls-isms-risk-assessment-treatment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-RISK-06
    • UC-RISK-07
    • UC-RISK-08
    • UC-RISK-09
    • UC-RISK-10
    • UC-RISK-04
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:d28392c2f1ee0bffec0f16bf8935ffe4a883954a3dbec02d0f981ced07f5dcee

            Connections