Defining the Risk Criteria: Strengthening Security Operations Through ISO 18788, ISO 31000, and ISO 27005

Introduction

In any effective Security Operations Management System (SOMS), as defined in ISO 18788:2015, the ability to manage risk is central to achieving organizational objectives and protecting stakeholders. At the heart of this process lies the definition of risk criteria—the benchmarks against which risks are evaluated. Risk criteria provide the foundation for consistent, transparent, and defensible decision-making. To achieve global best practice, ISO 18788 aligns with the principles of ISO 31000:2018 (Risk Management) and sector-specific standards like ISO/IEC 27005 (Information Security Risk Management), ensuring that security risk assessments are robust, systematic, and adaptable across domains.

Linking Risk Criteria with ISO Standards

ISO 18788: Security Operations Management

ISO 18788 requires organizations to define and document risk criteria that reflect their values, objectives, and operating environment. These criteria must account for legal obligations, human rights commitments, and operational realities.

ISO 31000:2018: Risk Management Principles

ISO 31000 emphasizes that risk criteria must be aligned with:

  • The objectives of the organization.
  • Stakeholder needs and expectations.
  • The external and internal context of operations.
  • The organization's risk appetite and tolerance.

ISO/IEC 27005: Information Security Risk Management

For information-related risks, ISO 27005 provides detailed guidance on establishing likelihood and consequence criteria tailored to confidentiality, integrity, and availability, ensuring that cyber and information threats are assessed with the same rigor as physical security risks.

Together, these standards ensure that security risk assessments are holistic, scalable, and embedded in the organization's governance structure.

Core Elements of Risk Criteria

Likelihood Criteria

  • Likelihood expresses the chance of an event occurring, either qualitatively (rare, possible, almost certain) or quantitatively (frequency/probability). Organizations must define scales that reflect both operational context and available data.

Consequence Criteria

Consequences measure the impact of a risk event on strategic, operational, financial, reputational, safety, or human rights objectives. Consequence scales must be clearly defined (e.g., negligible to catastrophic).

Risk Matrix (5x5 Example)

  • By combining likelihood and consequence, risks can be rated within a risk matrix (e.g., 5x5), creating categories such as Low, Medium, High, and Extreme. This provides a visual, standardized tool for prioritizing risks across departments.

Internal Control Effectiveness (ICE)

  • Risk criteria must also integrate the strength of internal controls. The ICE model evaluates whether preventive, detective, and corrective controls are effective, partially effective, or weak. This ensures that risk ratings reflect residual risk rather than just inherent risk.

Other Considerations

  • Risk Appetite and Tolerance: The level of risk the organization is willing to accept.
  • Regulatory and Contractual Obligations: Compliance requirements that may lower tolerance for certain risks.
  • Human Rights Impacts: Ensuring that risks to communities, employees, and stakeholders are assessed beyond financial or operational metrics.

Benefits of Defining Risk Criteria

  • Consistency - Provides a common language for decision-making across all levels of security operations.
  • Transparency - Ensures stakeholders understand how risks are measured and prioritized.
  • Integration - Aligns security risk assessments with enterprise-wide risk management and governance frameworks.
  • Continuous Improvement - Enables monitoring, review, and adaptation as the organizational context changes.

Conclusion

Defining risk criteria is a cornerstone of effective risk management under ISO 18788, directly supported by ISO 31000:2018 and ISO/IEC 27005. By establishing clear likelihood and consequence scales, using structured tools such as the 5x5 risk matrix, and embedding models like Internal Control Effectiveness (ICE), organizations can ensure that their security operations are strategically aligned, resilient, and ethically sound. In doing so, they not only protect assets but also uphold legal obligations, human rights, and stakeholder trust.