GOV-005 Risk Assessment
Description
Information security risks are identified and assessed on a defined schedule and when significant changes occur. Risk assessments document threats, vulnerabilities, likelihood, impact, and current controls, and results are used to prioritise treatment decisions.
Rationale
A repeatable risk assessment process is the mechanism by which an organisation identifies where its security investment should be directed. Without documented risk assessments, control selection is arbitrary.
Applicability (9 profiles)
164.308(a)(1)(ii)(A) is the most enforced specification in the rule and the one a healthcare customer asks for by name. Two things change for GOV-005 here: its scope has to be demonstrably every system holding electronic protected health information, and 164.306(b)(2) makes the entity's size and capabilities, its technical infrastructure and the cost of a measure recorded inputs to the choice of treatment, which GOV-005 does not currently name.
Annex point 2.1.2 fixes the process: a stated methodology, a risk tolerance level set against the risk appetite, maintained risk criteria, an all-hazards identification that reaches third parties and single points of failure, and cyber threat intelligence as an input to the analysis. Point 2.1.4 sets the review floor at at least annually and adds significant incidents as a trigger.
Framework Mappings (18)
| GRC-02 | Risk Management Program | informative |
| MDS-06 | Adversarial Attack Analysis | informative |
| GRC-02 | Risk Management Program | partial |
| GDPR-Art.32.2 | Risk-Based Security Assessment | partial |
| HIPAA-164.306.a | General Requirements | informative |
| HIPAA-164.306.b | Flexibility of Approach | partial |
| HIPAA-164.308.a.1.ii.A | Risk Analysis | full |
| HIPAA-164.308.a.1.ii.B | Risk Management | informative |
| 5.1 | Policies for information security | informative |
| NIS2-Art.21.1 | Appropriate and Proportionate Cybersecurity Risk-Management Measures | informative |
| NIS2-Art.21.2.a | Policies on Risk Analysis and Information System Security | informative |
| NIS2-CIR-13.2 | Protection Against Physical and Environmental Threats | informative |
| NIS2-CIR-13.3 | Perimeter and Physical Access Control | informative |
| NIS2-CIR-2.1 | Risk Management Framework | partial |
| NIS2-CIR-Art.2.2 | Proportionality and Documented Reasoning for Non-Application | informative |
| RA-3 | Risk Assessment | full |
| CC3.2 | COSO Principle 7: Identifies and Analyzes Risk | full |
| CC3.4 | COSO Principle 9: Identifies and Analyzes Significant Change | partial |
Evidence (2)
Completed risk assessment report documenting threats, vulnerabilities, likelihood, impact ratings, and current controls for in-scope information assets.
Example: Annual Information Security Risk Assessment Report (Google Drive / SharePoint), dated within the last 12 months, showing a named assessor, risk register extract, and treatment recommendations.
Test: Request the most recent risk assessment report. Verify: (1) the report is dated within the defined assessment interval, (2) it documents threats, vulnerabilities, likelihood, and impact for each assessed asset or domain, (3) current controls are noted against each risk, (4) treatment decisions (accept/mitigate/transfer/avoid) are recorded, (5) a named assessor is identified.
Risk register showing current risk inventory with likelihood, impact, and treatment status populated.
Example: Risk register (ISMS tool, spreadsheet, or GRC platform such as Vanta/Drata), with columns for risk ID, description, likelihood, impact, treatment decision, owner, and current status, reviewed within the last 12 months.
Test: Query or export the risk register. Verify: (1) risks identified in the most recent assessment are present, (2) each risk has a named owner, (3) treatment status is populated and current, (4) the register shows a last-reviewed date within the defined interval.
Questions (3)
Does your organisation conduct formal information security risk assessments on a defined schedule?
A risk assessment should document threats, vulnerabilities, likelihood, impact, current controls, and treatment decisions, produced by a named assessor.
How often is a full information security risk assessment conducted?
Most frameworks require annual assessment at minimum, plus ad hoc assessment on significant system or business changes.
Which of the following does your risk register record for each identified risk?
Options run from the most commonly held to the least. A register carrying ratings but no owner cannot be worked. One carrying no review date cannot be shown to reflect the risks as they stand rather than as they stood at the last assessment.