Two Approaches to Risk Assessment — Which One Is Right for Your Organization?
The Two Approaches
ISO 27005 provides two distinct approaches to risk assessment :
|
Approach |
Description |
Focus |
|
Asset-Based |
Evaluate threats to specific information assets |
Individual assets and their vulnerabilities |
|
Event-Based |
Focus on the broader threat landscape |
Events and their impact on the organization |
Asset-Based Risk Assessment
Definition: Asset-based assessment evaluates threats to specific information assets. It identifies what assets exist, what threats they face, and what vulnerabilities they have .
Process:
- Identify information assets
- Classify assets by criticality
- Identify threats to each asset
- Identify vulnerabilities
- Assess risk for each asset
When to use it:
- When you need to understand asset-specific risks
- When you have limited resources and need to prioritize assets
- When you're in a mature security program
Event-Based Risk Assessment
Definition: Event-based assessment focuses on the broader threat landscape. It identifies events that could impact the organization and assesses their likelihood and impact .
Process:
- Identify events that could impact the organization
- Assess likelihood of each event
- Assess impact of each event
- Prioritize events for risk treatment
When to use it:
- When you need a high-level view of risk
- When you're in a less mature program
- When you're starting from scratch
Pros and Cons
|
Dimension |
Asset-Based |
Event-Based |
|
Granularity |
High |
Medium |
|
Complexity |
High |
Medium |
|
Resource requirements |
High |
Medium |
|
Risk visibility |
Detailed |
Broad |
|
Implementation time |
Longer |
Faster |
Which Approach Is Right for You?
Start with Asset-Based if:
- You have a mature security program
- You need detailed risk visibility
- You have the resources for a comprehensive assessment
Start with Event-Based if:
- You're building a program from scratch
- You need a high-level view of risk
- You have limited resources
Combining Both Approaches
Many organizations use both approaches:
- Start with event-based for a high-level view
- Use asset-based for critical assets
- Integrate findings into a unified risk register
Conclusion
The right approach depends on your organization's maturity, resources, and regulatory requirements. Many organizations start with event-based and move to asset-based as they mature.
Action Items for Your Organization
- Assess your risk maturity
- Decide between asset-based and event-based
- Consider a combined approach
- Document your risk assessment methodology
- Implement risk assessments on your chosen schedule