What this is
What is an information security risk assessment?
What is an information security risk assessment?
A structured assessment of risks to the confidentiality, integrity and availability of information, identifying assets and their exposure, credible threats, existing controls and residual risk. Under ISO 27001 clause 6.1.2 the methodology must be defined, applied consistently and produce comparable results.
Does it cover operational technology?
It should, and increasingly must. NIS2 Article 21 requires an all-hazards approach covering cyber, physical, environmental and human threats to network and information systems, which for a manufacturer includes control systems, connected machinery and the operational technology that a purely IT-scoped assessment omits.
Scope
When is an information security risk assessment required?
This assessment covers risks to information and to network and information systems. Adjacent regimes address related but distinct obligations.
Use this template when
- Establishing the ISMS risk picture under ISO 27001, and reviewing it at planned intervals
- Assessing operational technology and connected machinery alongside IT systems
- Following a significant change: new system, new supplier, acquisition, or a change in processing
- After an incident or a near miss, including at a supplier
- Where NIS2 or an equivalent regime applies and the all-hazards scope must be demonstrated
Do not use it for
- Data protection impact assessment, which addresses risks to individuals from processing personal data
- Business continuity and disaster recovery planning, which respond to disruption rather than assessing likelihood
- Penetration testing and vulnerability scanning, which are technical assurance activities feeding this
- Supplier due diligence, which applies the assessment's conclusions to a specific third party
- Physical security assessment of the site, which this should reference where systems depend on it
Compliance mapping
Which ISO 27001 cl.6.1.2 requirements does this satisfy?
Information security combines a management system standard undergoing transition with an EU directive whose enforcement machinery is arriving unevenly.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27001 cl.6.1.2 | Information security risk assessment process with defined criteria, applied consistently and producing comparable results | Header |
| ISO 27001 cl.6.1.3 | Risk treatment, statement of applicability and risk treatment plan approved by risk owners | Controls |
| ISO 27001:2022 Annex A | 93 controls across organisational, people, physical and technological themes | Controls |
| NIS2 Article 21 | All-hazards risk management measures covering cyber, physical, environmental and human threats | Threats |
| NIS2 Article 20 | Management body approval of measures, oversight of implementation and accountability for breaches | Outcome |
| NIS2 Article 23 | Incident reporting cascade with early warning, incident notification and final report timescales | Outcome |
| GDPR Article 32 | Security of processing appropriate to risk, where personal data is involved | Assets and exposure |
| ISO 27001 cl.8.2 | Risk assessment performed at planned intervals and when significant changes occur | Header |
What it does not cover
- Data protection impact assessment, which addresses risk to individuals from processing rather than risk to the organisation.
- Business continuity planning, which addresses recovery rather than assessing exposure.
- Penetration testing and vulnerability management, which provide technical input to this assessment.
- Supplier due diligence, applying the assessment's conclusions to specific third parties.
- The incident reporting process, which under NIS2 has a specific cascade with defined timescales.
How to complete it
How to complete an information security risk assessment, step by step
Four things determine whether this assessment reflects the organisation rather than its IT department.
Include operational technology, control systems, connected equipment, building management systems and anything with a network interface on the production floor. For most operational businesses the largest availability exposure sits there, and a scope drawn around corporate IT will not find it.
NIS2's all-hazards approach is explicit about this and it is where assessments are usually thinnest. Loss of power or cooling, water ingress, physical access to a control cabinet, an engineer with standing remote access, and a supplier's technician with a laptop are all in scope and none are conventional cyber threats.
NIS2 transposition has been uneven. Only a small number of member states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Where you provide services across borders, each state's transposition governs your obligations there.
Article 20 places accountability on the management body for approving measures and overseeing implementation, with the possibility for essential entities of executives being temporarily barred from management functions. Approval therefore needs to be evidenced rather than assumed from a governance structure.
What auditors find
Most common information security risk assessment findings
Findings here concentrate on scope and on evidence of governance.
| Finding | Clause | What fixes it |
|---|---|---|
| Scope limited to corporate IT, excluding operational technology. | NIS2 Article 21 | Include control systems and connected equipment; the availability exposure usually sits there. |
| Physical, environmental and human threats not assessed. | NIS2 Article 21 | All-hazards is explicit; power, cooling, access and insider exposure belong in the assessment. |
| Operating under an expired ISO 27001:2013 certificate. | IAF transition rules | 2013 certificates became invalid on 31 October 2025; full recertification is now required. |
| Statement of applicability not updated for the 2022 Annex A structure. | ISO 27001:2022 | 93 controls across four themes replaced 114 across 14 domains; the mapping is substantial. |
| Management body approval not evidenced. | NIS2 Article 20 | Record approval and oversight; accountability sits with the management body personally. |
| Cross-border obligations assessed against the home state only. | NIS2 | Each member state where you provide services governs your obligations there. |
| Supply chain security not assessed. | NIS2 Article 21 | Supplier and service provider security is an explicit measure, not an optional extension. |
| Risk assessment not repeated after a significant change. | ISO 27001 cl.8.2 | Assess at planned intervals and on change; acquisitions and new systems both qualify. |
| Incident reporting timescales not built into the response process. | NIS2 Article 23 | The cascade has defined stages and timings; discovering them during an incident is too late. |
| Risk owners not identified for treatment decisions. | ISO 27001 cl.6.1.3 | Name risk owners; unowned residual risk has not been accepted by anyone. |
Case in point
Case in point: the standard expired and the directive arrived unevenly
Two things happened in parallel. The International Accreditation Forum set a three-year window for transition from ISO 27001:2013 to the 2022 revision, ending 31 October 2025. After that date a certificate referencing the 2013 standard is invalid, and organisations that missed the window face full recertification with Stage 1 and Stage 2 audits rather than the shorter transition path.
Meanwhile NIS2 required transposition into national law by 17 October 2024. Very few member states met the deadline. The Commission opened infringement proceedings against most of them in November 2024, issued reasoned opinions in May 2025, and by 2026 had escalated the slowest cases further. By mid-2026 the large majority of member states had transposed, with a handful still in legislative process.
For an operator with sites in several member states, that produced a period in which the same directive imposed different obligations in different places, with the applicable rules depending on each state's transposition rather than on the directive alone.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-035
- Archetype
- Assessment
- Record ID
- ISR-2026-000
- Scoring
- Residual band
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 27001 cl.6.1.2
- Links
- Links Enterprise risk, Business continuity
- Tags
- Security, Information
- Sections
- 5
- Fields
- 44
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
10 fieldsAssessment ID*
Auto sequence. Format ISR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Scope*
Assessed By*
Operational Technology Included*
- Yes3 pts
- No0 pts
Control Systems Are Rarely In The IT Assessment
The systems that run refrigeration, weighing and metal detection are increasingly networked and almost never covered by the corporate security assessment.
Assets and exposure
6 fieldsInformation Assets Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Control Systems Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Network Segmentation Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Remote Access Points Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Supplier Remote Access Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Legacy Systems Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Threats
6 fieldsRansomware Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Phishing Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Insider Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Supply Chain Compromise Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Physical Access To Systems Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Loss Of Availability Impact Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Controls
6 fieldsPatching Regime In Place*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Backups Tested*
- Yes3 pts
- Partly1 pt
- No0 pts
Access Control Enforced*
- Yes3 pts
- Partly1 pt
- No0 pts
Multi Factor Authentication Used*
- Yes3 pts
- Partly1 pt
- No0 pts
Monitoring And Alerting In Place*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Incident Response Plan Exists*
- Yes3 pts
- Partly1 pt
- No0 pts
Outcome
16 fieldsResidual Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
High Risks Identified*
Control Systems Adequately Protected*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Enterprise Risk Register*
Continuity Plan Aligned*
- Yes3 pts
- No0 pts
Next Review Due*
Risk Assessment
Risk ID
Format RSK-2026-00000.
Links to FDN-012 Risk ID
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
IT*
Signature*
Site Manager*
Second Signature*
CMP-035 · record IDs look like ISR-2026-000 · Links Enterprise risk, Business continuity
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The assessment defines the ISMS risk picture. What fails is the scope that stopped at the IT boundary and the approval nobody evidenced.
Holds the assessment against the asset inventory including operational technology, and tracks the statement of applicability against the current Annex A structure.
Brings control systems, connected machinery and building systems into the asset picture, which IT-drawn inventories consistently omit.

Flags changes, acquisitions and new suppliers as assessment triggers, and tracks obligations by the jurisdiction in which services are provided.
Covers supplier and service provider security, including standing remote access held by engineering partners.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Information Security Risk Assessment definitions and key terms
- All-hazards approach
- The NIS2 Article 21 requirement to protect network and information systems against cyber, physical, environmental and human threats.
- Essential and important entities
- The two NIS2 categories, differing in supervisory regime and in the sanctions available.
- Statement of applicability
- The ISO 27001 document recording which Annex A controls apply, why, and their implementation status.
- Operational technology
- Control systems, connected machinery and instrumentation, frequently outside the scope of IT-drawn assessments.
- Risk owner
- The person accountable for a risk and for accepting residual risk after treatment.
- Management body accountability
- The NIS2 Article 20 requirement that management approves measures and oversees implementation, with personal consequences.
- Transposition
- A member state enacting a directive into national law, which for NIS2 has proceeded unevenly and at different speeds.
- Incident reporting cascade
- The NIS2 sequence of early warning, incident notification and final report, each with its own timescale.
FAQ
Frequently asked questions about information security risk assessment
What happened to ISO 27001:2013 certificates?+
They became invalid on 31 October 2025, at the end of the three-year transition window set by the International Accreditation Forum. Organisations that completed a transition audit before then hold a 2022 certificate. Those that did not now require full recertification against the 2022 standard, involving Stage 1 and Stage 2 audits rather than the shorter transition route.
What changed in the 2022 revision?+
The management system clauses saw relatively modest change. Annex A was restructured substantially: 114 controls across 14 domains became 93 controls across four themes covering organisational, people, physical and technological controls. The practical consequence is that the statement of applicability requires remapping rather than editing.
Does NIS2 apply to us?+
It depends on sector, size and, critically, on which member states you operate in, because obligations are set by each state's transposing law. Transposition has been uneven: very few states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Reported counts vary between sources and change as legislation progresses.
What does the all-hazards approach require?+
Under Article 21, protection of network and information systems against cyber, physical, environmental and human threats rather than digital threats alone. For an operational business that means power and cooling, physical access to control cabinets, environmental exposure, standing remote access held by engineers and suppliers, and operational technology generally.
What is the significance of management accountability?+
NIS2 Article 20 requires the management body to approve cybersecurity risk management measures and oversee their implementation, and makes it accountable for breaches. Competent authorities can order audits at the entity's expense and, for essential entities, temporarily prohibit individuals from exercising management functions. Approval therefore needs to be evidenced.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Data Protection and Information Security
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Protection Impact Assessment
Assesses the privacy impact of a new system or monitoring activity before it is introduced
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline
System Access Review
Reviews who has access to which systems and at what privilege level
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
More in Information Security
System Access Review
Reviews who has access to which systems and at what privilege level
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
Backup and Recovery Test Record
Records a test that backups can actually be restored, not merely that they ran

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3 and 8.2, and Annex A
- IAF transition requirements for ISO/IEC 27001:2022, transition ending 31 October 2025
- Directive (EU) 2022/2555 (NIS2), particularly Articles 20, 21 and 23
- ENISA technical guidance on NIS2 implementation and control mappings
- GDPR Article 32, security of processing
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.