Risk assessment: the clause the question tests
Whether security risks are assessed on a method, recorded and treated.
How the customer usually asks it
example"Do you perform a formal information security risk assessment at least annually?"
Anchor clauses
4 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | clause 6.1.2 Information security risk assessment (named, not quoted) |
| SOC 2 (Trust Services Criteria) | CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed |
| SIG (Shared Assessments) | domain A Risk Assessment and Treatment Program |
| HIPAA Security Rule (45 CFR 164) | 164.308(a)(1)(ii)(A) Risk Analysis (Required) |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The risk assessment method, the current risk register with owners and treatment decisions, and the date of the last full assessment.
The clauses, with what an assessor asks for
SOC 2 CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managedNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Risk register produced annually as a compliance artefact with no evidence it drove any decision; Analysis reduced to a colour rating with no reasoning recorded behind likelihood or impact
Source: SOC 2 (Trust Services Criteria)
SIG domain A Risk Assessment and Treatment ProgramWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.
Where answers usually fall short: Risk register stale beyond annual cycle; No documented risk acceptance approvals at appropriate level
Source: SIG (Shared Assessments)
HIPAA 164.308(a)(1)(ii)(A) Risk Analysis (Required)Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.
Where answers usually fall short: Risk analysis is checklist-style, not threat-based; Not refreshed after material changes
Source: HIPAA Security Rule (45 CFR 164)