workflow
ISMS Risk Assessment & Treatment Cycle
Perform an ISO 27005 information security risk assessment and treatment cycle for a defined ISMS scope. The recurring cycle instance attaches to the existing Process item (process_type=security_process) that represents the ISMS scope — enrich that item, never create a duplicate; the risk register it produces is the set of Risk items the run creates and updates. The cycle: establish context and risk criteria, identify information security risks, analyze and evaluate them against the criteria, select treatment options, draft the risk treatment plan, obtain residual-risk acceptance, and retain the documented information. In scope: risk identification through treatment planning and residual-risk acceptance for the ISMS boundary. Out of scope: the Statement of Applicability control-applicability determination and control operating-effectiveness testing, which are handled downstream. This workflow has no upstream workflow — its boundary and inventory are initial inputs: the in-scope business processes are existing Process items, while the asset/information inventory and risk criteria are uploaded documents (no native Asset type). It produces the named deliverables — the current risk register (Risk items), the Risk Treatment Plan (RTP), and the SoA inputs — handed off to the ISO 27001 SoA Review & Controls Assessment workflow.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- risk-management
- domains
- controls
- standards
- iso-27001
- iso-31000
- sourceTemplateId
- workflow-library:controls-isms-risk-assessment-treatment
- releaseId
- sha256:c41960df9620b050aea3d8cff5dd0752208c8d27ff1a7e18f76a4295d2f8b1f6
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=controls-isms-risk-assessment-treatment
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-RISK-06
- UC-RISK-07
- UC-RISK-08
- UC-RISK-09
- UC-RISK-10
- UC-RISK-04
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:c41960df9620b050aea3d8cff5dd0752208c8d27ff1a7e18f76a4295d2f8b1f6
Connections
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-09 — Select, plan, and implement risk treatments
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-04 — Define objectives and business context for risk assessment
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-10 — Maintain a risk register and report the portfolio view
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-06 — Perform periodic enterprise risk assessments