risk-assessment

Identify information security risks and generate a Risk Register per ISO 27001:2022 Clause 6.1.2.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill risk-assessment-gombing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-assessment
Source: https://github.com/gombing/ISO27001Agent/tree/main/risk-assessment
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill risk-assessment-gombing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill guides practitioners through a formal, standards-based risk identification and analysis process aligned with ISO 27001:2022 Clause 6.1.2, producing a documented Risk Register.

Core Features & Use Cases

  • Risk criteria setup: Establish a consistent scoring model (5×5 by default) and risk acceptance thresholds for executive reporting.
  • Seeded risk identification: Seed risks from prior Gap and Annex findings to accelerate risk discovery and tracking.
  • Asset category scoping: Confirm in-scope asset categories and generate category-specific risk scenarios for rapid review.
  • Risk register generation: Produce a structured risk register linking risks to owners, controls gaps, and treatment directions for /risk-treatment planning.

Quick Start

Run the risk-assessment skill after completing /gap-assessment and /annex-review to generate a seeded risk register and begin scoring.

Frequently Asked Questions about risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an ISO 27001 risk register for Clause 6.1.2?

To generate an ISO 27001 risk register for Clause 6.1.2, you need to identify information security risks across standard asset categories and document them using a formal risk scoring model. This produces a structured register linking risks to owners and control gaps.

What's the best way to document information security risks using a 5x5 matrix?

Documenting information security risks with a 5x5 matrix involves establishing a consistent scoring model and risk acceptance thresholds to evaluate impact and likelihood. This methodology drives executive reporting and clarifies the risk acceptance criteria for your organization.

Do I need to complete a gap assessment before identifying ISO 27001 risks?

Yes, completing a gap assessment and annex review before identifying ISO 27001 risks is required. These prior findings seed your risk scenarios across asset categories, accelerating risk discovery and ensuring accurate tracking within your formal risk register.

Can I use a custom risk scoring methodology instead of the default 5x5 matrix?

Yes, you can use a client-defined alternative risk scoring methodology instead of the default 5x5 matrix. The risk methodology must be clearly documented to ensure consistent evaluation and to support formal risk treatment planning and executive reporting.

How does risk identification support the ISO 27001 risk treatment process?

Risk identification supports the risk treatment process by producing a structured risk register that links identified risks to owners, controls gaps, and treatment directions. This documented output directly seeds the subsequent treatment planning steps.

What is ISO 27001 risk acceptance criteria and when do I need it?

ISO 27001 risk acceptance criteria defines the threshold for acceptable risks within your organization's risk scoring model. You need it during risk assessment to determine which information security risks require treatment and which can be accepted.