Skip to content

Class: RiskAssessmentProcess

The documented risk assessment process per Clause 6.1.2, defining criteria and methodology for identifying, analyzing, and evaluating risks.

URI: iso27001:RiskAssessmentProcess

 classDiagram
    class RiskAssessmentProcess
    click RiskAssessmentProcess href "../RiskAssessmentProcess/"
      DocumentedInformation <|-- RiskAssessmentProcess
        click DocumentedInformation href "../DocumentedInformation/"

      RiskAssessmentProcess : approved_by

      RiskAssessmentProcess : approved_date

      RiskAssessmentProcess : assessment_criteria

      RiskAssessmentProcess : assessment_frequency

      RiskAssessmentProcess : assessment_methodology

      RiskAssessmentProcess : author

      RiskAssessmentProcess : classification

      RiskAssessmentProcess : created_date

      RiskAssessmentProcess : description

      RiskAssessmentProcess : document_reference

      RiskAssessmentProcess : document_type





        RiskAssessmentProcess --> "0..1" DocumentType : document_type
        click DocumentType href "../DocumentType/"



      RiskAssessmentProcess : effective_date

      RiskAssessmentProcess : id

      RiskAssessmentProcess : impact_scale

      RiskAssessmentProcess : likelihood_scale

      RiskAssessmentProcess : modified_date

      RiskAssessmentProcess : name

      RiskAssessmentProcess : owner

      RiskAssessmentProcess : retention_period

      RiskAssessmentProcess : review_date

      RiskAssessmentProcess : risk_acceptance_criteria

      RiskAssessmentProcess : risk_matrix

      RiskAssessmentProcess : status

      RiskAssessmentProcess : trigger_events

      RiskAssessmentProcess : version

Inheritance

Slots

Name Cardinality and Range Description Inheritance
risk_acceptance_criteria 0..1
String
Criteria for accepting risks direct
assessment_criteria 0..1
String
Criteria for performing risk assessments direct
assessment_methodology 0..1
String
Methodology used for risk assessment direct
likelihood_scale 0..1
String
Scale used for likelihood rating direct
impact_scale 0..1
String
Scale used for impact rating direct
risk_matrix 0..1
String
Risk matrix or calculation method direct
assessment_frequency 0..1
String
Planned frequency of risk assessments direct
trigger_events *
String
Events that trigger risk assessment outside planned schedule direct
document_type 0..1
DocumentType
Classification of the documented information DocumentedInformation
document_reference 0..1
String
Unique reference number for document control DocumentedInformation
author 0..1
String
Person who created the document DocumentedInformation
owner 0..1
String
Person accountable for the document content and maintenance DocumentedInformation
approved_by 0..1
String
Person who approved the document DocumentedInformation
approved_date 0..1
Date
Date when the document was approved DocumentedInformation
effective_date 0..1
Date
Date when the document becomes effective DocumentedInformation
review_date 0..1
Date
Date when the document is due for review DocumentedInformation
status 0..1
String
Current status of the document or entity DocumentedInformation
classification 0..1
String
Information classification level DocumentedInformation
retention_period 0..1
DurationType
Duration for which the document is retained DocumentedInformation
id 1
Uriorcurie
Unique identifier for this entity instance NamedEntity
name 1
String
Human-readable name or title NamedEntity
description 0..1
String
Detailed description of the entity NamedEntity
created_date 0..1
Date
Date when the entity was created NamedEntity
modified_date 0..1
Date
Date when the entity was last modified NamedEntity
version 0..1
String
Version identifier for the entity NamedEntity

Usages

used by used in type used
InformationSecurityManagementSystem risk_assessment_process range RiskAssessmentProcess

In Subsets

Comments

  • Defines reusable criteria, scales, and methods for risk assessments
  • Supports repeatable assessment execution over time
  • Reference: ISO/IEC 27001:2022 Clause 6.1.2. ISO/IEC standards text is copyright ISO - not reproduced here.

Identifier and Mapping Information

Annotations

property value
iso27001_clause 6.1.2
mandatory true

Schema Source

  • from schema: https://w3id.org/lmodel/iso27001

Mappings

Mapping Type Mapped Value
self iso27001:RiskAssessmentProcess
native iso27001:RiskAssessmentProcess

LinkML Source

Direct

name: RiskAssessmentProcess
annotations:
  iso27001_clause:
    tag: iso27001_clause
    value: 6.1.2
  mandatory:
    tag: mandatory
    value: 'true'
description: The documented risk assessment process per Clause 6.1.2, defining criteria
  and methodology for identifying, analyzing, and evaluating risks.
comments:
- Defines reusable criteria, scales, and methods for risk assessments
- Supports repeatable assessment execution over time
- 'Reference: ISO/IEC 27001:2022 Clause 6.1.2. ISO/IEC standards text is copyright
  ISO - not reproduced here.'
in_subset:
- risk_management
- documented_information
from_schema: https://w3id.org/lmodel/iso27001
is_a: DocumentedInformation
slots:
- risk_acceptance_criteria
- assessment_criteria
- assessment_methodology
- likelihood_scale
- impact_scale
- risk_matrix
- assessment_frequency
- trigger_events

Induced

name: RiskAssessmentProcess
annotations:
  iso27001_clause:
    tag: iso27001_clause
    value: 6.1.2
  mandatory:
    tag: mandatory
    value: 'true'
description: The documented risk assessment process per Clause 6.1.2, defining criteria
  and methodology for identifying, analyzing, and evaluating risks.
comments:
- Defines reusable criteria, scales, and methods for risk assessments
- Supports repeatable assessment execution over time
- 'Reference: ISO/IEC 27001:2022 Clause 6.1.2. ISO/IEC standards text is copyright
  ISO - not reproduced here.'
in_subset:
- risk_management
- documented_information
from_schema: https://w3id.org/lmodel/iso27001
is_a: DocumentedInformation
attributes:
  risk_acceptance_criteria:
    name: risk_acceptance_criteria
    annotations:
      iso27001_clause:
        tag: iso27001_clause
        value: 6.1.2 a) 1)
    description: Criteria for accepting risks.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: risk_acceptance_criteria
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  assessment_criteria:
    name: assessment_criteria
    annotations:
      iso27001_clause:
        tag: iso27001_clause
        value: 6.1.2 a) 2)
    description: Criteria for performing risk assessments.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: assessment_criteria
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  assessment_methodology:
    name: assessment_methodology
    description: Methodology used for risk assessment.
    comments:
    - Supports consistent, valid, and comparable results per 6.1.2 b)
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: assessment_methodology
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  likelihood_scale:
    name: likelihood_scale
    description: Scale used for likelihood rating.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: likelihood_scale
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  impact_scale:
    name: impact_scale
    description: Scale used for impact rating.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: impact_scale
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  risk_matrix:
    name: risk_matrix
    description: Risk matrix or calculation method.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: risk_matrix
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  assessment_frequency:
    name: assessment_frequency
    description: Planned frequency of risk assessments.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: assessment_frequency
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
  trigger_events:
    name: trigger_events
    description: Events that trigger risk assessment outside planned schedule.
    comments:
    - Per 8.2, when significant changes are proposed or occur
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: trigger_events
    owner: RiskAssessmentProcess
    domain_of:
    - RiskAssessmentProcess
    range: string
    multivalued: true
  document_type:
    name: document_type
    description: Classification of the documented information.
    in_subset:
    - documented_information
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: document_type
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: DocumentType
  document_reference:
    name: document_reference
    description: Unique reference number for document control.
    comments:
    - Per 7.5.2 a) identification and description
    examples:
    - value: ISMS-POL-001
    - value: RA-2024-003
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: document_reference
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: string
  author:
    name: author
    description: Person who created the document.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: author
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: string
  owner:
    name: owner
    description: Person accountable for the document content and maintenance.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: owner
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: string
  approved_by:
    name: approved_by
    description: Person who approved the document.
    comments:
    - Per 7.5.2 c) review and approval
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: approved_by
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    - StatementOfApplicability
    range: string
  approved_date:
    name: approved_date
    description: Date when the document was approved.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: approved_date
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    - RiskTreatmentPlan
    range: date
  effective_date:
    name: effective_date
    description: Date when the document becomes effective.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: effective_date
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: date
  review_date:
    name: review_date
    description: Date when the document is due for review.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: review_date
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    - ManagementReview
    range: date
  status:
    name: status
    description: Current status of the document or entity.
    comments:
    - Examples include draft, approved, active, superseded, archived
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: status
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    - Nonconformity
    - CorrectiveAction
    - ImprovementOpportunity
    range: string
  classification:
    name: classification
    description: Information classification level.
    comments:
    - Per A.5.12, classification based on confidentiality, integrity, availability
    examples:
    - value: confidential
    - value: internal
    - value: public
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: classification
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    - Asset
    range: string
  retention_period:
    name: retention_period
    description: Duration for which the document is retained.
    comments:
    - Per 7.5.3 f) retention and disposition
    - Use ISO 8601 duration notation such as P1Y or P90D
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: retention_period
    owner: RiskAssessmentProcess
    domain_of:
    - DocumentedInformation
    range: duration type
  id:
    name: id
    description: Unique identifier for this entity instance.
    comments:
    - Should use consistent URI/CURIE format across the dataset
    examples:
    - value: iso27001:risk-001
    - value: iso27001:control-5.1
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    identifier: true
    alias: id
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: uriorcurie
    required: true
  name:
    name: name
    description: Human-readable name or title.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: name
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: string
    required: true
  description:
    name: description
    description: Detailed description of the entity.
    comments:
    - Should provide sufficient detail for understanding without external reference
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: description
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: string
  created_date:
    name: created_date
    description: Date when the entity was created.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: created_date
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: date
  modified_date:
    name: modified_date
    description: Date when the entity was last modified.
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: modified_date
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: date
  version:
    name: version
    description: Version identifier for the entity.
    comments:
    - Supports document control requirements per 7.5.3 e)
    examples:
    - value: '1.0'
    - value: 2.3.1
    from_schema: https://w3id.org/lmodel/iso27001
    rank: 1000
    alias: version
    owner: RiskAssessmentProcess
    domain_of:
    - NamedEntity
    range: string