Training module

Auditing Information Security Risk Management

Evaluate asset–threat–vulnerability logic, risk treatment decisions, and traceability to controls and the Statement of Applicability

Information SecurityManagement System Auditor
Auditor interviewing system owner about information security risks, representing auditing of ISMS risk management, risk reasoning, treatment decisions, and traceability to controls under ISO/IEC 27001.

Does your audit go beyond checking risk registers to judging risk reasoning and treatment choices?

In many audits, risk management looks “complete” on paper but breaks down when you follow one risk from context to treatment and control operation. This module builds a practical audit lens for testing whether risk reasoning is credible, decisions are explainable, and traceability holds under scrutiny.

Overview

What this module is about

ISO/IEC 27001 expects risk assessment and risk treatment to drive the information security management system (ISMS), not to exist as standalone documentation. In practice, auditors often encounter generic asset lists, recycled threat catalogues, inconsistent scoring, and a Statement of Applicability (SoA) that cannot be traced back to specific risks and treatment decisions.

This standard-specific auditing module focuses on how to audit ISMS risk management where information security logic materially matters: asset–threat–vulnerability reasoning, treatment decision quality, and traceability from risks to chosen controls (including Annex A) and the SoA. It does not re-teach generic risk management methods or generic audit techniques; it applies an audit judgement lens to ISO/IEC 27001 risk management expectations.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

aim to audit whether ISMS risk management actually drives security decisions.

want to test asset–threat–vulnerability reasoning, not just risk register completeness.

follow risks from context through treatment decisions to controls and the SoA.

strengthen judgement on risk acceptance, prioritisation, and traceability.

seek audit findings that reveal weak risk reasoning and systemic gaps.

It may not be the best fit if you…

primarily want to design or improve risk assessment or treatment methods.

expect generic risk management frameworks or scoring models.

focus on facilitating workshops or producing risk documentation.

are unwilling to challenge formally complete but weak risk rationales.

Agenda

What is taught

7 parts
01What makes ISMS risk management audit-ready

Assesses whether risk management functions as a decision and traceability system, not whether a risk register exists or “looks complete”.

02Testing asset–threat–vulnerability reasoning

Tests plausibility of assets in scope, realistic threat paths, and meaningful vulnerabilities, including boundary and dependency risks from shared services, cloud, suppliers, and shadow assets.

03Risk assessment outputs that hold under audit

Checks internal consistency across scope, assets, incidents, weaknesses, and results, and uses targeted sampling to expose weak or convenience-driven reasoning.

04Judging risk treatment decisions

Evaluates whether treatment choices (reduce, retain, avoid, share) are coherent, authorised, and documented, and whether risk acceptance is credible in terms of authority, rationale, residual risk, and review triggers.

05Traceability to controls and the Statement of Applicability (SoA)

Verifies traceability from risks to control selection and applicability rationale, and tests SoA completeness and indicators of “control theatre”.

06Evidence trails from documentation to operation

Follows evidence from treatment decisions into projects, control implementation, and operational reality, and identifies disconnects between plans, controls, and actual operation.

07Case-based audit simulation

Applying the learned concepts, methods, and approaches in a realistic case setting

Outcomes

Learning outcomes

01

Evaluate whether asset–threat–vulnerability logic is credible and fit for decision-making in an ISMS

02

Test internal consistency of risk assessment results using practical audit checks and targeted sampling heuristics

03

Assess whether risk treatment decisions are explainable, authorised, and reviewable

Verify end-to-end traceability from risks to controls and to the Statement of Applicability (SoA)

Identify common systemic failure modes in ISO/IEC 27001 risk management and recognise early warning signals

Build effective audit trails and evidence requests that connect risk documentation to operational control reality

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Auditing Information Security Risk Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-IS-A-01
Download fact sheet (PDF, 5.1 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Auditing Information Security Risk Management · HAM-IS-A-01

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Auditing Information Security Risk Management · HAM-IS-A-01

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.