You are on page 1of 1

Information Handling Risk Assessment

<Short Name> ISO 27001:2013

Information Asset Information Owner

Description of Information
Handling Requirement

Assessment of risk before risk reduction Assessment of risk after risk reduction
measures measures Respons
Information Asset at Risk Description of Risk Likelihood: Severity: Exposure Measures to reduce risk Likelihood: Severity: Exposure -ibility
Index: Index:
L1 – L5 S1 = S5 (1 – 25) L1 – L5 S1 = S5 (1 – 25)

Likelihood: L1 = Improbable, L2 = Remote, L3 = Occasional, L4 = Probable, L5 =


Frequent

Severity: S1 = Negligible, S2 = Minor, S3 = Serious, S4 = Critical, S5 =


Catastrophic

Exposure Index: 1 – 4 = Low, 6 – 12 = Medium, 15 – 25 = High

Rev 0.0 Page 1 of 1

You might also like