In this blog, Wayne Armstrong, Senior Consultant at URM, explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes and ensure they meet the Standard’s requirements in full. He examines how organisations can align risk management with business objectives, identify and protect critical information assets, improve transparency and inclusivity within the risk assessment process, and respond more effectively to emerging threats. The blog also highlights the importance of managing third-party and cloud-related risks, helping organisations maximise the value and effectiveness of their risk management activities.
Strong information risk management sits at the heart of an effective ISO 27001 implementation. Most organisations understand the need to identify and treat risks, but many miss opportunities to gain greater value from the process because key requirements are overlooked or risk management is treated as a compliance exercise rather than a business tool.
The following five must-dos will help ensure that your approach not only meets the requirements of ISO 27001, but also delivers meaningful benefits to the organisation.
Align Risk Management With Business Objectives
This is the difference between information risk management that is performed as a box-ticking exercise and risk management that genuinely benefits the business. If your organisation needs to gain ISO 27001 certification with minimal delays, perhaps due to a client requirement, simply meeting the Standard’s requirements may be an appropriate approach. However, as your ISMS matures, you should consider how it can be improved to provide greater value to the organisation; a key aspect of this is starting to perform ISO 27001 risk management through the lens of your organisation’s strategic objectives and goals.
When your organisation identifies opportunities it wants to pursue, there may be uncertainty about whether they are worth the associated risks. Effective, objective-driven information risk management identifies what could go wrong, the potential consequences, and what can be put in place to reduce the impact or likelihood of adverse outcomes. Risk management then becomes something that helps you achieve business objectives, instead of a source of red tape or bureaucracy as it is often viewed, leading to enhanced buy-in and support from senior management.
For example, if your organisation is planning to expand its services, start by looking at the information assets involved in the new service, how that information will be processed and communicated, where it will be stored, and who will have access to it. Once these assets and processes are understood, you can assess the risks associated with them and the potential impact if those risks materialise. If being first to market is a key objective, for instance, you would need to consider the likelihood and consequences of confidential plans being disclosed to a competitor. This allows suitable controls and protections to be implemented without undermining the business’ ability to achieve its goals.
Ultimately, information risk management should help your organisation pursue new opportunities with confidence. Rather than preventing the business from moving forward, effective risk management helps it do so safely, with the right protections in place and without exposing itself to unnecessary or unacceptable levels of risk.
There may, however, be occasions where the risks associated with a particular activity are so significant that they warrant escalation to senior leadership and reconsideration of whether to proceed. For example, an activity may expose the organisation to substantial regulatory, legal, financial, or reputational consequences that potentially outweigh the benefits it can provide. In such circumstances, leaders should be provided with a clear understanding of the potential impacts so they can make an informed decision. This may result in the activity being stopped altogether or, where the opportunity remains strategically important, being redesigned in a way that reduces the risk to an acceptable level.
Identify Important Information Assets
Your organisation only has a finite amount of resources, and identifying and protecting all of your organisation’s information can create issues around over-securing and wasting resources where they are not necessarily needed. However, there will be pieces of information within your organisation that are more important than others, and therefore need a different degree of protection.
To identify the information assets that matter most, you first need to understand your critical business processes. These are the processes that support your organisation’s key objectives and keep it operating. For example, the process behind revenue collection is likely to be critical because it keeps money coming into the organisation. Once these processes have been identified, you can then determine which information assets support them and which need the highest level of protection. These assets will usually form your important or critical information and should be prioritised when implementing appropriate security controls.
Confidentiality, integrity and availability (CIA)
One common misconception is that this is all about confidentiality; while this will be true of certain information assets, others may be important/require protection in different ways. It may be that some information is important because it must always remain accurate, or always available and able to be used by anyone who needs it. In other words, you need to establish whether each piece of information is critical from the perspective of confidentiality, integrity and/or availability (CIA), and protect it accordingly.
For example, new product specifications will need to be kept confidential so that competitors do not gain access, and will therefore require the implementation of controls that help ensure this confidentiality is maintained. On the other hand, it would not be necessary to keep staff canteen menus confidential, but the integrity of information related to allergens and dietary requirements is critical, so measures would need to be in place to ensure they are always kept accurate and up to date.
Need for Transparency and Inclusivity
These are two areas that are sometimes missed by organisations when performing risk assessments and risk management. Transparency is about the results of the ISO 27001 risk assessment, and the need to keep people informed. Key stakeholders, such as senior management, regulators, and certain customers, will have a vested interest in knowing what risks have been identified and what steps are being taken to address them. As such, these parties will need to be made aware of risk assessment outputs, instead of risk information being retained solely within the risk management team or other isolated areas of the organisation.
Inclusivity is about who is involved in the risk assessment process. We have encountered organisations that believe all elements of an information risk assessment can be completed by a single individual or team, without involving other areas of the business. The problem is that the assessment may then be based on assumptions about how other parts of the organisation work, where information is stored, and how it is used, rather than what is actually happening in practice. By involving people from across the organisation, you gain a clearer picture of business activities, information flows, dependencies, and day-to-day operational practices.
When gathering information from across the organisation, it’s important to reassure teams that they won’t face repercussions for sharing what is really happening, including where a policy or process isn’t being followed. This makes people more likely to describe the reality of how work is done, rather than only what should be happening according to documented policies and processes. Only by understanding the gaps between documentation and reality can you begin to determine why policies or processes are not being followed in practice, and make informed changes so they better reflect the way the business operates.
Threat Intelligence
This is a fairly subtle change that was introduced in the 2022 version of the Standard that has more significant repercussions than many organisations are aware of, particularly those that have been certified for a long time.
Previously, it was perfectly acceptable to perform periodic risk assessments and only revisit these in line with the predetermined schedule (on an annual basis for most organisations.) However, with the introduction of Control 5.7 – Threat intelligence in ISO 27001:2022, this is no longer necessarily the case. Now, the expectation is that you gather information about threats, determine whether those threats apply to you (i.e., turn the information into intelligence), and take action based upon that intelligence – without waiting for the next annual risk assessment to do so.
Instead, you need to feed the threat intelligence you receive into your risk management process on an ongoing basis, and update your risk registers as necessary. In some scenarios, this may be required to ensure that your organisation is aware of new or enhanced threats increasing a previously acceptable risk in value, meaning that other action needs to be taken as soon as is feasible. As such, risk management in ISO 27001 has become a more dynamic process, rather than an iterative one. This is not to say that the iterative process has disappeared; you still need full, periodic risk assessments to review the risks that have previously been accepted but have not been impacted by any threats. However, it does mean that you can no longer solely rely on scheduled risk activities.
Third-Party Risk
Annex A contains a few controls that cover the management of third parties, and while much of this work will be the responsibility of the procurement team or equivalent, one of these controls (namely 5.19 – Information security in supplier relationships) is partially focused on understanding the risk associated with third parties. As such, it makes sense to ensure that your risk management processes are able to be used for evaluating third party risks.
For clarity, this is not about performing a risk assessment for your suppliers, but instead the risk of working with those suppliers, i.e., understanding which information of yours they will have access to, how they will use that information, the processes they have in place to protect your information, etc. With an understanding of these aspects, you will be able to categorise your suppliers in terms of the risk they present to your organisation. It may be that certain suppliers are categorised as high-risk as they have direct access to your information systems, while third parties such as local taxi firms or office stationery suppliers would likely be considered low risk.
Third-party information security risk remains your organisation’s risk, regardless of where the information is processed. If information handled by an internal team is assessed as high risk, information processed externally should be treated with the same level of care where the risk is comparable. The same criteria should be used to escalate the risk and ensure that appropriate mitigations are implemented.
Cloud-based suppliers
It is important that cloud suppliers are approached in the same way as traditional suppliers. It’s very easy to engage third parties operating in the cloud; in many cases, you will be able to sign up to a cloud-based service provider within minutes. These suppliers can represent a significant risk depending on the services they provide and information shared with them.
However, due to the ease with which these services can be procured and deployed, any user across your organisation could engage cloud service providers without understanding the need to determine the risk they present. As such, all staff should be made aware that cloud services must not be adopted without following your organisation's supplier management and risk assessment processes. Where individuals are not responsible for risk management activities, they should engage the appropriate personnel to ensure that any proposed service is properly assessed, approved, and onboarded before organisational information is shared or processed.

Conclusion
Information risk management is one of the most important elements of ISO 27001 and one of the areas most capable of delivering value beyond certification. By ensuring that risk management supports business objectives, prioritises critical information, includes the right stakeholders, incorporates threat intelligence, and addresses third-party risks, organisations can build a process that not only satisfies the Standard's requirements but also strengthens security and decision-making across the business.
How URM Can Help
With over 20 years of experience supporting organisations in achieving and maintaining certification to ISO 27001, URM provides practical, expert-led guidance across every stage of the Standard’s lifecycle.
Gap analysis and risk assessment
Helping you understand your current position and prioritise action:
- Conducting an ISO 27001 gap analysis to establish your current conformance level, assessing your information security practices against the Standard, identifying areas for improvement and providing reccommendations
- Assisting with your ISO 27001 risk assessment using Abriska 27001, our proven risk management tool.
Implementation and internal audit
Delivering hands-on support to build and validate your ISMS:
- Assisting with ISO 27001 implementation, including development of policies, processes, and ISMS infrastructure tailored to your organisation
- Delivering ISO 27001 internal audit services, whether as a pre-certification audit, a full three-year audit programme, or focused reviews of specific controls
- Identifying nonconformities and supporting effective remediation to ensure certification readiness.
Training and ongoing support
Providing continued expertise to maintain and improve your ISMS:
- Offering flexible ISO 27001 support, including our virtual Chief Information Security Officer (vCISO) service for senior-level information security guidance and leadership
- Delivering ISO 27001 training courses to build internal capability and strengthen your organisation’s security culture.
A short, free, non‑commitment call can help you clarify scope, understand regulatory expectations, and align your approach across standards such as ISO 42001 and NIST AI RMF. Early guidance often saves time and avoids fragmented compliance efforts.
Whether you are at an early planning stage or preparing for audit and assurance activities, we offer a free introductory call to help you assess risks, responsibilities, and the most proportionate route forward.
You do not need a fully defined programme to start the conversation. We offer a free, no‑obligation call to help you understand SOC 2 requirements, assess your current position, and identify practical next steps.
URM’s blog explains the legal, regulatory & contractual controls in ISO 27001 & how they can be implemented in full conformance with the Standard.
This blog takes a look at onboarding information systems. When onboarding is mentioned will conclude it’s referring to people but there is a lot more to think

What are the Benefits of Implementing ISO 27001? We dig a bit deeper on the benefits that are gained from implementing the standard.


