018 Principles
Value creation and protection, integration, structured approach, customisation to context, inclusion of stakeholders, dynamic response, best available information, plus human and cultural factors – the purpose is to create and protect value.
02Framework
Leadership and commitment at the centre, surrounded by the cycle of integration, design, implementation, evaluation and improvement.
03Context & communication
External and internal context, risk criteria and continuous communication and consultation form the basis of every risk decision.
04Risk assessment
Identification, analysis and evaluation of risk – the methodological core on which ISO/IEC 27005 builds for information security.
05Risk treatment
Selecting and implementing options to modify risk – avoid, reduce, share or accept – including the evaluation of residual risk.
06Monitoring & reporting
Continuous monitoring and review, plus recording and reporting, secure traceability and drive improvement.