Knowella

Information Security Risk Assessment Template

Two things have changed the character of this assessment for operational businesses. NIS2 requires an all-hazards approach covering physical, environmental and human threats rather than only digital ones, and it makes the management body personally accountable, with the possibility of executives being temporarily barred from management functions.

KnowComplyAssessmentCMP-03544 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27001 cl.6.1.2
Workspace
KnowComply
Form type
Assessment
ISO 27001:2013
Invalid since 31 October 2025
NIS2 Article 21
All-hazards, not just cyber

The short version

  • ISO 27001:2013 certificates became invalid on 31 October 2025. Organisations that missed the transition now require full recertification with Stage 1 and Stage 2 audits rather than a transition audit.
  • The 2022 revision restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, which changes the statement of applicability substantially.
  • NIS2 required transposition by 17 October 2024. Very few member states met it, the Commission opened infringement proceedings against most, and by mid-2026 the great majority had transposed with several still in process.
  • Where you operate across borders you are governed by the transposition status of each member state in which you provide services, not by your home state alone.
  • NIS2 Article 20 places accountability on the management body, and competent authorities can order audits at the entity's expense and, for essential entities, temporarily ban executives from management functions.
  • Article 21's all-hazards approach reaches beyond IT into physical, environmental and human threats, which is where operational businesses are usually least assessed.

What this is

What is an information security risk assessment?

What is an information security risk assessment?

A structured assessment of risks to the confidentiality, integrity and availability of information, identifying assets and their exposure, credible threats, existing controls and residual risk. Under ISO 27001 clause 6.1.2 the methodology must be defined, applied consistently and produce comparable results.

Does it cover operational technology?

It should, and increasingly must. NIS2 Article 21 requires an all-hazards approach covering cyber, physical, environmental and human threats to network and information systems, which for a manufacturer includes control systems, connected machinery and the operational technology that a purely IT-scoped assessment omits.

Scope

When is an information security risk assessment required?

This assessment covers risks to information and to network and information systems. Adjacent regimes address related but distinct obligations.

Use this template when

  • Establishing the ISMS risk picture under ISO 27001, and reviewing it at planned intervals
  • Assessing operational technology and connected machinery alongside IT systems
  • Following a significant change: new system, new supplier, acquisition, or a change in processing
  • After an incident or a near miss, including at a supplier
  • Where NIS2 or an equivalent regime applies and the all-hazards scope must be demonstrated

Do not use it for

  • Data protection impact assessment, which addresses risks to individuals from processing personal data
  • Business continuity and disaster recovery planning, which respond to disruption rather than assessing likelihood
  • Penetration testing and vulnerability scanning, which are technical assurance activities feeding this
  • Supplier due diligence, which applies the assessment's conclusions to a specific third party
  • Physical security assessment of the site, which this should reference where systems depend on it

Compliance mapping

Which ISO 27001 cl.6.1.2 requirements does this satisfy?

Information security combines a management system standard undergoing transition with an EU directive whose enforcement machinery is arriving unevenly.

ClauseRequirementWhere it lands
ISO 27001 cl.6.1.2Information security risk assessment process with defined criteria, applied consistently and producing comparable resultsHeader
ISO 27001 cl.6.1.3Risk treatment, statement of applicability and risk treatment plan approved by risk ownersControls
ISO 27001:2022 Annex A93 controls across organisational, people, physical and technological themesControls
NIS2 Article 21All-hazards risk management measures covering cyber, physical, environmental and human threatsThreats
NIS2 Article 20Management body approval of measures, oversight of implementation and accountability for breachesOutcome
NIS2 Article 23Incident reporting cascade with early warning, incident notification and final report timescalesOutcome
GDPR Article 32Security of processing appropriate to risk, where personal data is involvedAssets and exposure
ISO 27001 cl.8.2Risk assessment performed at planned intervals and when significant changes occurHeader

What it does not cover

  • Data protection impact assessment, which addresses risk to individuals from processing rather than risk to the organisation.
  • Business continuity planning, which addresses recovery rather than assessing exposure.
  • Penetration testing and vulnerability management, which provide technical input to this assessment.
  • Supplier due diligence, applying the assessment's conclusions to specific third parties.
  • The incident reporting process, which under NIS2 has a specific cascade with defined timescales.

How to complete it

How to complete an information security risk assessment, step by step

Four things determine whether this assessment reflects the organisation rather than its IT department.

Scope to network and information systems, not to IT

Include operational technology, control systems, connected equipment, building management systems and anything with a network interface on the production floor. For most operational businesses the largest availability exposure sits there, and a scope drawn around corporate IT will not find it.

Cover physical, environmental and human threats

NIS2's all-hazards approach is explicit about this and it is where assessments are usually thinnest. Loss of power or cooling, water ingress, physical access to a control cabinet, an engineer with standing remote access, and a supplier's technician with a laptop are all in scope and none are conventional cyber threats.

Establish where each member state's rules apply

NIS2 transposition has been uneven. Only a small number of member states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Where you provide services across borders, each state's transposition governs your obligations there.

Record management body approval

Article 20 places accountability on the management body for approving measures and overseeing implementation, with the possibility for essential entities of executives being temporarily barred from management functions. Approval therefore needs to be evidenced rather than assumed from a governance structure.

What auditors find

Most common information security risk assessment findings

Findings here concentrate on scope and on evidence of governance.

FindingClauseWhat fixes it
Scope limited to corporate IT, excluding operational technology.NIS2 Article 21Include control systems and connected equipment; the availability exposure usually sits there.
Physical, environmental and human threats not assessed.NIS2 Article 21All-hazards is explicit; power, cooling, access and insider exposure belong in the assessment.
Operating under an expired ISO 27001:2013 certificate.IAF transition rules2013 certificates became invalid on 31 October 2025; full recertification is now required.
Statement of applicability not updated for the 2022 Annex A structure.ISO 27001:202293 controls across four themes replaced 114 across 14 domains; the mapping is substantial.
Management body approval not evidenced.NIS2 Article 20Record approval and oversight; accountability sits with the management body personally.
Cross-border obligations assessed against the home state only.NIS2Each member state where you provide services governs your obligations there.
Supply chain security not assessed.NIS2 Article 21Supplier and service provider security is an explicit measure, not an optional extension.
Risk assessment not repeated after a significant change.ISO 27001 cl.8.2Assess at planned intervals and on change; acquisitions and new systems both qualify.
Incident reporting timescales not built into the response process.NIS2 Article 23The cascade has defined stages and timings; discovering them during an incident is too late.
Risk owners not identified for treatment decisions.ISO 27001 cl.6.1.3Name risk owners; unowned residual risk has not been accepted by anyone.

Case in point

Case in point: the standard expired and the directive arrived unevenly

Two things happened in parallel. The International Accreditation Forum set a three-year window for transition from ISO 27001:2013 to the 2022 revision, ending 31 October 2025. After that date a certificate referencing the 2013 standard is invalid, and organisations that missed the window face full recertification with Stage 1 and Stage 2 audits rather than the shorter transition path.

Meanwhile NIS2 required transposition into national law by 17 October 2024. Very few member states met the deadline. The Commission opened infringement proceedings against most of them in November 2024, issued reasoned opinions in May 2025, and by 2026 had escalated the slowest cases further. By mid-2026 the large majority of member states had transposed, with a handful still in legislative process.

For an operator with sites in several member states, that produced a period in which the same directive imposed different obligations in different places, with the applicable rules depending on each state's transposition rather than on the directive alone.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

44fields
5 sections
Reference
CMP-035
Archetype
Assessment
Record ID
ISR-2026-000
Scoring
Residual band
Direction
Low is good
Singleton
Yes
Basis
ISO 27001 cl.6.1.2
Links
Links Enterprise risk, Business continuity
Tags
Security, Information
Sections
5
Fields
44
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format ISR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Scope*

Users

Assessed By*

Single Choice

Operational Technology Included*

Scored
  • Yes3 pts
  • No0 pts
Info

Control Systems Are Rarely In The IT Assessment

The systems that run refrigeration, weighing and metal detection are increasingly networked and almost never covered by the corporate security assessment.

Assets and exposure

6 fields
Single Choice

Information Assets Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Control Systems Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Network Segmentation Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Remote Access Points Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Supplier Remote Access Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Legacy Systems Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Threats

6 fields
Single Choice

Ransomware Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Phishing Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Insider Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Supply Chain Compromise Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Physical Access To Systems Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Loss Of Availability Impact Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Controls

6 fields
Single Choice

Patching Regime In Place*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Backups Tested*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Access Control Enforced*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Multi Factor Authentication Used*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Monitoring And Alerting In Place*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Incident Response Plan Exists*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Outcome

16 fields
Single Choice

Residual Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Numeric Answer

High Risks Identified*

Scored
Single Choice

Control Systems Adequately Protected*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Feeds Enterprise Risk Register*

YesNo
Single Choice

Continuity Plan Aligned*

Scored
  • Yes3 pts
  • No0 pts
Date & Time

Next Review Due*

Pick List

Risk Assessment

OptionalFrom FDN-012 Risk Title
Text

Risk ID

OptionalLinked

Format RSK-2026-00000.

Links to FDN-012 Risk ID

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

IT*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-035 · record IDs look like ISR-2026-000 · Links Enterprise risk, Business continuity

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment defines the ISMS risk picture. What fails is the scope that stopped at the IT boundary and the approval nobody evidenced.

KnowComply

Holds the assessment against the asset inventory including operational technology, and tracks the statement of applicability against the current Annex A structure.

KnowMaintain

Brings control systems, connected machinery and building systems into the asset picture, which IT-drawn inventories consistently omit.

Ella
Ella

Flags changes, acquisitions and new suppliers as assessment triggers, and tracks obligations by the jurisdiction in which services are provided.

KnowContractor

Covers supplier and service provider security, including standing remote access held by engineering partners.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Information Security Risk Assessment definitions and key terms

All-hazards approach
The NIS2 Article 21 requirement to protect network and information systems against cyber, physical, environmental and human threats.
Essential and important entities
The two NIS2 categories, differing in supervisory regime and in the sanctions available.
Statement of applicability
The ISO 27001 document recording which Annex A controls apply, why, and their implementation status.
Operational technology
Control systems, connected machinery and instrumentation, frequently outside the scope of IT-drawn assessments.
Risk owner
The person accountable for a risk and for accepting residual risk after treatment.
Management body accountability
The NIS2 Article 20 requirement that management approves measures and oversees implementation, with personal consequences.
Transposition
A member state enacting a directive into national law, which for NIS2 has proceeded unevenly and at different speeds.
Incident reporting cascade
The NIS2 sequence of early warning, incident notification and final report, each with its own timescale.

FAQ

Frequently asked questions about information security risk assessment

What happened to ISO 27001:2013 certificates?+

They became invalid on 31 October 2025, at the end of the three-year transition window set by the International Accreditation Forum. Organisations that completed a transition audit before then hold a 2022 certificate. Those that did not now require full recertification against the 2022 standard, involving Stage 1 and Stage 2 audits rather than the shorter transition route.

What changed in the 2022 revision?+

The management system clauses saw relatively modest change. Annex A was restructured substantially: 114 controls across 14 domains became 93 controls across four themes covering organisational, people, physical and technological controls. The practical consequence is that the statement of applicability requires remapping rather than editing.

Does NIS2 apply to us?+

It depends on sector, size and, critically, on which member states you operate in, because obligations are set by each state's transposing law. Transposition has been uneven: very few states met the October 2024 deadline, the Commission opened infringement proceedings against most, and by mid-2026 the large majority had transposed with several still in process. Reported counts vary between sources and change as legislation progresses.

What does the all-hazards approach require?+

Under Article 21, protection of network and information systems against cyber, physical, environmental and human threats rather than digital threats alone. For an operational business that means power and cooling, physical access to control cabinets, environmental exposure, standing remote access held by engineers and suppliers, and operational technology generally.

What is the significance of management accountability?+

NIS2 Article 20 requires the management body to approve cybersecurity risk management measures and oversee their implementation, and makes it accountable for breaches. Competent authorities can order audits at the entity's expense and, for essential entities, temporarily prohibit individuals from exercising management functions. Approval therefore needs to be evidenced.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3 and 8.2, and Annex A
  • IAF transition requirements for ISO/IEC 27001:2022, transition ending 31 October 2025
  • Directive (EU) 2022/2555 (NIS2), particularly Articles 20, 21 and 23
  • ENISA technical guidance on NIS2 implementation and control mappings
  • GDPR Article 32, security of processing

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.