Asset-Based vs. Event-Based Risk Assessment

Two Approaches to Risk Assessment — Which One Is Right for Your Organization?


The Two Approaches

ISO 27005 provides two distinct approaches to risk assessment :

Approach

Description

Focus

Asset-Based

Evaluate threats to specific information assets

Individual assets and their vulnerabilities

Event-Based

Focus on the broader threat landscape

Events and their impact on the organization

Asset-Based Risk Assessment

Definition: Asset-based assessment evaluates threats to specific information assets. It identifies what assets exist, what threats they face, and what vulnerabilities they have .

Process:

  1. Identify information assets
  2. Classify assets by criticality
  3. Identify threats to each asset
  4. Identify vulnerabilities
  5. Assess risk for each asset

When to use it:

  • When you need to understand asset-specific risks
  • When you have limited resources and need to prioritize assets
  • When you're in a mature security program

Event-Based Risk Assessment

Definition: Event-based assessment focuses on the broader threat landscape. It identifies events that could impact the organization and assesses their likelihood and impact .

Process:

  1. Identify events that could impact the organization
  2. Assess likelihood of each event
  3. Assess impact of each event
  4. Prioritize events for risk treatment

When to use it:

  • When you need a high-level view of risk
  • When you're in a less mature program
  • When you're starting from scratch

Pros and Cons

Dimension

Asset-Based

Event-Based

Granularity

High

Medium

Complexity

High

Medium

Resource requirements

High

Medium

Risk visibility

Detailed

Broad

Implementation time

Longer

Faster

Which Approach Is Right for You?

Start with Asset-Based if:

  • You have a mature security program
  • You need detailed risk visibility
  • You have the resources for a comprehensive assessment

Start with Event-Based if:

  • You're building a program from scratch
  • You need a high-level view of risk
  • You have limited resources

Combining Both Approaches

Many organizations use both approaches:

  1. Start with event-based for a high-level view
  2. Use asset-based for critical assets
  3. Integrate findings into a unified risk register

Conclusion

The right approach depends on your organization's maturity, resources, and regulatory requirements. Many organizations start with event-based and move to asset-based as they mature.


Action Items for Your Organization

  • Assess your risk maturity
  • Decide between asset-based and event-based
  • Consider a combined approach
  • Document your risk assessment methodology
  • Implement risk assessments on your chosen schedule