• Risk register
  • EBIOS RM
  • ISO 27005
  • NIST CSF

Your first risk register: a proportionate method aligned with EBIOS RM and ISO 27005

Risk registers for SMEs: what ISO 27001 (clauses 6.1.2 and 8.2) and NIS2 require, how to start with EBIOS RM workshop 1 (scoping and security baseline), which columns to keep and which pitfalls to avoid. An iterative method aligned with ISO/IEC 27005:2022.

Komplyo4 min read

Risk assessment appears in most of the frameworks that apply to European SMEs. Clause 6.1.2 of ISO/IEC 27001 requires a defined, applied and documented assessment process. Article 21 of the NIS2 directive lists "policies on risk analysis" first among the expected measures. And customer security questionnaires regularly ask for the date and scope of the last risk analysis.

In an SME, this work falls to the security representative, whose time is limited. The question is therefore not whether a risk register is needed, but what depth is defensible for a first cycle, and how to build on it afterwards. The reference methods, EBIOS Risk Manager and ISO/IEC 27005, both describe an iterative process. A proportionate first register, reviewed at planned intervals, fits their logic. An exhaustive register produced once and then abandoned does not.

What the texts actually require

Clause 6.1.2 of ISO/IEC 27001:2022 requires defining risk criteria, identifying risks related to the loss of confidentiality, integrity and availability, analysing their consequences and likelihood, then evaluating and prioritising them. The results are retained as documented information: that is the role the register plays. Clause 8.2 adds that the assessment is repeated at planned intervals or when significant changes occur.

No method is imposed. ISO/IEC 27005:2022, the application guide, describes two identification approaches: event-based (building risk scenarios without a detailed prior inventory) and asset-based (starting from the inventory and examining threats and vulnerabilities). On the NIST CSF 2.0 side, risk assessment corresponds to the ID.RA category and risk management strategy to GV.RM, which connects the register to the rest of the security evaluation.

EBIOS RM: five workshops, and a usable first tier

EBIOS Risk Manager, the method published by ANSSI, the French cybersecurity agency, structures the analysis in five workshops: scoping and security baseline, risk sources, strategic scenarios, operational scenarios, risk treatment. Its version 1.5, published in March 2024, aligns the vocabulary and the approach with ISO/IEC 27005:2022.

The method rests on two complementary pillars. The security baseline, established through conformity with existing reference frameworks, covers common risks, including accidental and environmental ones. The scenario approach, developed in the following workshops, addresses intentional and targeted threats.

For a first register, workshop 1 is the starting tier: delimit the scope, identify business values and feared events, evaluate the baseline against a reference framework (the ANSSI hygiene guide, NIST CSF 2.0) and record the gaps. This work already produces a documented, prioritised view of common risks. Workshops 2 to 5 deepen the intentional scenarios in later cycles, when the scope or the exposure justifies it.

The structure of the register

One entry per risk scenario, following the event-based logic of ISO 27005, with the following columns: scenario description, likelihood, impact, resulting risk level, chosen treatment option (reduce, retain, avoid or share, among the options described by ISO 27005), associated measures, owner and deadline, date of the next review.

The event-based approach keeps the register readable: an SME covers its feared events with a few dozen scenarios at most, where an asset-based approach produces hundreds of rows, most of which carry no decision. The treatment decision is what an auditor looks for: a register without a treatment column documents concerns, not risk management.

The pitfalls of the first cycle

Three problems recur in first registers. Asset exhaustivity first: inventorying every workstation and every application before formulating a single scenario delays the first treatment decision without improving its quality. The event-based approach, accepted by ISO 27005, avoids that detour in the first cycle.

The one-off register next. Clause 8.2 of ISO 27001 requires repeated assessments, and ISO 27005 describes monitoring and review as continuous activities. A register dated two years ago, with no traced review, is treated as a nonconformity in an audit and read the same way in a supplier assessment.

Finally, confusion with the statement of applicability. The register records risks and treatment decisions; the statement of applicability justifies the inclusion or exclusion of each Annex A control. The two documents connect through the treatment plan, but neither replaces the other.

Where to start

The risk register is one of the documents generated from the Komplyo assessment: 16 typical SME threat scenarios, pre-filled from your answers. The residual likelihood derives from your measured NIST CSF 2.0 maturity; what remains is adjusting the business impact, which only you know. The associated treatment plan follows the format of ISO 27001 clause 6.1.3 (treatment option, retained measures, owner per risk) and the register updates with each assessment cycle, which materialises the review required by clause 8.2. The free diagnostic (23 questions, around 5 minutes) provides the starting point.

Sources

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.