Risk Methodology

Last modified by Lee Pedley on 2026/09/21 21:59

       

Risk methodology
This application uses a configurable 5 x 5 management model. It is a local methodology, not a prescribed ISO/IEC 27001 scoring method.

Likelihood (1-5)

  1. Rare
  2. Unlikely
  3. Possible
  4. Likely
  5. Almost certain

Impact (1-5)

  1. Insignificant
  2. Minor
  3. Moderate
  4. Major
  5. Severe

Configured bands

Low: score <= 4
Moderate: <= 9
High: <= 14
Critical: > 14
Residual risk review threshold: >= 15

Edit thresholds

5 x 5 score matrix

Impact / Likelihood12345
55
Moderate
10
High
15
Critical
20
Critical
25
Critical
44
Low
8
Moderate
12
High
16
Critical
20
Critical
33
Low
6
Moderate
9
Moderate
12
High
15
Critical
22
Low
4
Low
6
Moderate
8
Moderate
10
High
11
Low
2
Low
3
Low
4
Low
5
Moderate

How to use the risk record

  1. Describe the asset/process, threat and vulnerability.
  2. Assess inherent likelihood and impact before treatment.
  3. Select a treatment decision and link relevant controls.
  4. Create treatment records for mitigation actions.
  5. Assess residual likelihood and impact after considering treatment.
  6. Use status and target date to manage the lifecycle; accepted risk should reflect an authorised decision under your governance process.