Module 3 · Qualitative Risk Assessment — ISO 27005 / NIST 800-30 Done Well

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 14, 2026
4 min read
Read as
100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Most Indian enterprises do qualitative risk assessment — likelihood × impact scoring on a 5×5 matrix — and most do it badly. The matrix becomes a heatmap that decorates board decks. This module covers ISO 27005 and NIST SP 800-30 done well: meaningful scoring scales, calibrated rater training, and the outputs that actually drive decisions.

Why this module exists. Done well, qualitative risk assessment is cheap, repeatable, and good enough for 90% of decisions. Done badly, it is theatre. The difference is in the scoring rigour, not the framework choice.

What ISO 27005 and NIST SP 800-30 actually prescribe

Both frameworks define a process: identify assets, identify threats, identify vulnerabilities, assess likelihood, assess impact, compute risk, treat. The frameworks are loose on the scoring scale — that is the practitioner’s choice, and the choice matters.

The 5×5 matrix done well

A 5×5 likelihood-impact matrix is the most-common scoring approach. The pattern fails because scales are vague:

Likelihood Vague (bad) Calibrated (good)
5 — Very Likely “Will probably happen” ≥1 event/year
4 — Likely “May happen” 1 event in 1-3 years
3 — Possible “Could happen” 1 event in 3-10 years
2 — Unlikely “Unlikely” 1 event in 10-30 years
1 — Rare “Negligible” <1 event in 30 years

The calibrated version turns “Very Likely” from a feeling into a falsifiable claim. Two raters scoring the same risk converge much faster.

Calibrated impact scoring

Impact Calibrated definition
5 — Catastrophic >₹50 Cr loss; regulatory cease-and-desist; CEO removal-level reputational damage
4 — Major ₹10-50 Cr; significant regulator action; material media coverage
3 — Moderate ₹1-10 Cr; warning/penalty; localised media
2 — Minor ₹10L-1 Cr; corrective directives; internal-only impact
1 — Insignificant <₹10L; no external visibility

Adjust the rupee thresholds to your organisation’s scale. The key is that two assessors agree on which row a specific scenario belongs to.

The rater training problem

Even with calibrated scales, raters drift. Studies in risk-assessment psychology show:

  • Without training, two raters agree on the same risk score about 40% of the time.
  • With a 2-hour training using worked examples and post-session calibration, agreement reaches 75-85%.
  • Annual recalibration keeps it there.

Run a 2-hour training annually for everyone who scores risks. Use 10 worked examples, ask raters to score independently, then walk through the rationale. This is the most-cost-effective quality investment in qualitative risk programmes.

The risk-register output

The risk assessment produces a register. Minimum-viable fields:

  • Risk ID (stable identifier; ID survives renames)
  • Risk title and one-sentence description
  • Risk owner (named individual)
  • Likelihood score with rationale (1-2 sentences)
  • Impact score with rationale
  • Inherent risk score (L × I)
  • Current controls — what is in place
  • Residual risk score (after current controls)
  • Target residual score
  • Treatment plan (what to do to close the gap)
  • Treatment owner and target date
  • Last reviewed date; next review date

The rationale field is what distinguishes a working register from a heatmap exporter. “Likelihood 4 because we saw 3 similar incidents in sector ISAC last year” is auditable; “likelihood 4” is not.

Inherent vs residual — the distinction that matters

Inherent risk = the risk assuming no controls. Residual risk = the risk given existing controls. Auditors want both. The gap between them is where you measure control effectiveness over time.

A common failure: scoring only residual. The auditor asks “what if a control failed?” — you cannot answer because you do not have the inherent baseline. Always score both, every time.

Risk treatment — the four options

Treatment When appropriate
Mitigate Implement / improve controls to reduce L or I
Transfer Insurance, contractual transfer to vendor
Accept Risk is within appetite; documented acceptance with owner sign-off
Avoid Stop the activity that creates the risk

Common failure modes

  • Static register. Risk reviewed at creation, never again. Half the risks become stale within a year.
  • Owner is “the security team.” Risks need named individual owners with authority over the relevant controls.
  • Heatmap-driven prioritisation. The 4×4 cells of “red” risks tied for priority. Use the raw score (e.g., 4×4=16 vs 5×3=15) plus risk-owner judgement.
  • Risk register disconnected from controls. Each risk should map to specific controls in your control framework (ISO 27001 Annex A, NIST 800-53, your internal taxonomy). The mapping is what makes the register actionable.

Key takeaways

  • 5×5 matrix works if the scales are calibrated to falsifiable definitions.
  • Rater training annually; raises agreement from ~40% to ~80%.
  • Risk-register fields: rationale for scores is the distinguishing detail.
  • Score inherent AND residual; auditors and quality require both.
  • Four treatment options: mitigate, transfer, accept, avoid. Acceptance always with documented owner sign-off.
DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants