# Information risk management procedure

Source: https://aestech.com.au/policy-templates/#information-risk-management-procedure
Markdown URL: https://aestech.com.au/policy-templates/information-risk-management-procedure.md

The clause 6.1.2/6.1.3 and 8.2/8.3 engine: risk identification, analysis scales, evaluation, treatment, acceptance and review.

Frameworks: ISO 27001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This procedure defines how [Company Pty Ltd] identifies, analyses, evaluates and treats information security risks, per ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3, 8.2 and 8.3, so that risk decisions are consistent, repeatable and produce comparable results over time.

2. Scope
All information assets, processes, people, suppliers and technology within the ISMS scope statement.

3. Risk criteria
3.1 Likelihood scale (1 to 5): 1 Rare (less than once in 5 years), 2 Unlikely (once in 2 to 5 years), 3 Possible (once a year), 4 Likely (several times a year), 5 Almost certain (monthly or more).
3.2 Impact scale (1 to 5) considering confidentiality, integrity and availability: 1 Negligible, 2 Minor (limited internal disruption), 3 Moderate (customer impact or cost above [$10k]), 4 Major (regulatory report, cost above [$100k]), 5 Severe (existential, mass data breach).
3.3 Risk score = likelihood x impact. Acceptance threshold: scores of [6] or below may be accepted by the risk owner; [8 to 12] require [ISMS Manager] approval; above [12] require [top management] approval.

4. Risk identification
4.1 The [ISMS Manager] runs a full assessment at least annually and a targeted assessment on significant change (new system, supplier, market, or major incident).
4.2 Identify risks by considering assets and their owners, threats, vulnerabilities, incident history, audit findings and interested party requirements. Every risk gets a named risk owner.

5. Risk analysis and evaluation
5.1 Rate likelihood and impact using section 3 scales, taking existing controls into account (current risk).
5.2 Compare scores against the acceptance threshold and rank risks to produce a prioritised list for treatment.

6. Risk treatment
6.1 For each risk above threshold choose: modify (apply controls), retain (accept with approval), avoid (stop the activity), or share (insurance, outsourcing, contracts).
6.2 Where modifying, select controls, compare them against Annex A to confirm nothing necessary has been overlooked, and update the Statement of Applicability with inclusion and exclusion justifications.
6.3 Produce a risk treatment plan: risk ID, chosen option, controls, owner, due date, expected residual score.
6.4 Obtain risk owner approval of the plan and explicit acceptance of residual risks, recorded with name and date.

7. Risk register
Maintain the register in [tool/spreadsheet] with columns: ID, asset or process, description, threat, vulnerability, likelihood, impact, score, owner, treatment option, controls, residual score, acceptance approver, next review date.

8. Monitoring and review
Review the full register at least [quarterly]; report movements, new risks and overdue treatments to management review. Reassess any risk on relevant incident or control failure.

9. Roles and responsibilities
[ISMS Manager]: method, facilitation, register. Risk owners: ratings, treatment decisions, acceptance. [Top management]: approves criteria and high risk acceptances.

10. Records
Retain assessments, treatment plans and acceptance records for at least [3] years in [location].

11. Review
Review this procedure and the criteria in section 3 annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date].
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md