ISO 27001: Myth vs. reality – Myth 2: The risk assessment is just a formal audit point
In many companies, the idea persists that the ISO 27001 risk assessment is primarily a formal part of certification. Some organizations regard the risk analysis as a one-off mandatory task that must be completed before the audit in order to achieve certification. Once the certificate has been issued, the topic often loses attention in practice. However, this myth leads to significant misinterpretation of the standard and can compromise the effectiveness of the overall information security management system.
The reality is completely different. Risk analysis is at the heart of any effective ISMS. Without a well-founded, realistic and continuously updated risk assessment, ISO 27001 loses its purpose. The standard is not designed to simply generate a certificate. It is intended to enable companies to understand the actual threats to their information assets and select suitable measures. This is why risk analysis is the core process that controls all other activities in the ISMS.
It is also a common misconception that ISO 27001 requires the creation of a complete catalog of all conceivable risks. This is not the intention of the standard. Rather, the requirements are aimed at ensuring that companies identify the risks that are relevant to them. The focus is on the risks that could actually affect the organization and not on theoretical scenarios. A good risk assessment should provide a realistic and objective picture of the actual threat situation.
In practice, however, many risk analyses remain abstract and detached from reality. Some companies rely exclusively on very general risk descriptions that bear little relation to their own processes, systems and value creation procedures. They often work with interchangeable standard lists that have little real significance. Although such an approach makes it possible to pass an audit, it does not really protect against real threats. This is because threats and vulnerabilities are only significant if they are considered in the context of the company itself.
A sensible approach to risk assessment always starts with the business processes and information assets that are essential to the organization. Only when it is clear which processes are critical to the business and what data is being processed can it be assessed where vulnerabilities and risks arise. It is equally important to consider real threats, not just theoretical or rarely occurring scenarios. Threats can consist of technical vulnerabilities, misconfigurations, internal errors, supplier dependencies or external factors. It is crucial that the assessment relates to reality and does not just consist of forms.
An effective risk assessment should answer key questions. These include, for example What events could realistically harm our company? Which risks are most relevant to our current business situation? Which of our existing or planned measures actually and demonstrably reduce risks? These questions are not only important for the audit, but also for management and strategic decision-making. They form the basis for making risks transparent and making appropriate decisions.
Another common mistake is to view risk assessment as a purely documentary task. Many companies create spreadsheets and risk matrices because they believe this is the sole purpose of the process. However, the purpose of risk assessment is not documentation. It is merely proof that the organization has understood its risks and is drawing the right conclusions from them. The actual aim is to manage information security in a well-founded and comprehensible manner. Measures from Appendix A or alternative measures will only be effective if they are selected on the basis of a genuine risk assessment.
If companies ignore the risk assessment after certification or only carry it out superficially, this creates a deceptive sense of security. Certification alone does not protect against attacks, data loss or business interruptions. What counts is the actual practice. Threats are constantly changing. Technologies evolve. New applications are introduced, new service providers are added and internal processes change. Once a risk profile has been established, it is therefore never permanently valid. It must be regularly reviewed and updated to ensure that the ISMS remains effective.
Risk assessment is therefore a continuous process that should be integrated into overall corporate management. This means that risks in projects, changes to the IT landscape, new supplier relationships or organizational changes must always be taken into account. The ISMS will only be successful in the long term if the risk assessment is understood as a tool that supports managers and specialist departments in their decisions.
A purely audit-driven approach may work in the short term, but in the long term it leads to risks being overlooked or misjudged. Companies may then fulfill the formal requirements, but are still exposed to considerable risks. The standard is deliberately designed not to promote a checklist mentality, but to require systematic and fact-based thinking about risks. It demands transparency, traceability and a comprehensible justification for the selection of measures.
An effective risk assessment helps companies to set priorities and use resources wisely. Instead of treating all possible risks with equal intensity, a good analysis makes it possible to focus on the really relevant threats. This not only increases the level of security, but also the efficiency of security measures. At the same time, the risk analysis supports communication between IT, management and specialist departments because it creates a common basis for decisions.
Anyone who views the risk assessment merely as a mandatory task for obtaining the certificate is missing the real point of ISO 27001. Information security is not a project, but a permanent process. The certificate is only an external sign of a management system that must be practiced within the company. The quality of the risk analysis determines whether the ISMS really works or whether it merely serves the purpose of formal compliance.
Myth 3 on risk assessment and its practical implementation follows in the next part of this series.






