Security Questionnaire Mapper
Governance and policy ยท question family

Risk assessment: the clause the question tests

Whether security risks are assessed on a method, recorded and treated.

How the customer usually asks it

example

"Do you perform a formal information security risk assessment at least annually?"

Read this question

Anchor clauses

4 frameworks
FrameworkAnchor clause
ISO/IEC 27001:2022clause 6.1.2 Information security risk assessment (named, not quoted)
SOC 2 (Trust Services Criteria)CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed
SIG (Shared Assessments)domain A Risk Assessment and Treatment Program
HIPAA Security Rule (45 CFR 164)164.308(a)(1)(ii)(A) Risk Analysis (Required)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The risk assessment method, the current risk register with owners and treatment decisions, and the date of the last full assessment.

The clauses, with what an assessor asks for

SOC 2 CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The risk assessment covering the entity, its subsidiaries, divisions and operating units, and relevant external factors; The risk register with likelihood, impact, analysis and the determined response for each risk; Evidence of the involvement of appropriate levels of management in the assessment; Evidence of the frequency of assessment and of reassessment when conditions changed; Evidence risk responses were implemented, with owners and completion status
Where answers usually fall short: Risk register produced annually as a compliance artefact with no evidence it drove any decision; Analysis reduced to a colour rating with no reasoning recorded behind likelihood or impact
Source: SOC 2 (Trust Services Criteria)
SIG domain A Risk Assessment and Treatment Program

What it asks for, in one line (the standard's own text is not quoted here):

Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.

Evidence an assessor expects: Risk management policy and procedure; Current risk register with owners; Treatment plans with target dates and approvals; Risk committee minutes
Where answers usually fall short: Risk register stale beyond annual cycle; No documented risk acceptance approvals at appropriate level
Source: SIG (Shared Assessments)
HIPAA 164.308(a)(1)(ii)(A) Risk Analysis (Required)

Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.

Evidence an assessor expects: Documented risk analysis report; Risk analysis methodology aligned to NIST SP 800-30; Periodic refresh schedule; Evidence of ePHI scoping
Where answers usually fall short: Risk analysis is checklist-style, not threat-based; Not refreshed after material changes
Source: HIPAA Security Rule (45 CFR 164)

Other families in governance and policy