i-Prot

Frameworks · ISO 31000:2018

ISO 31000: manage risk with clear principles and a clear process.

We adopt ISO 31000:2018 to give your organization a risk-management framework — of principles and process, not certifiable, but the foundation of everything.

diagram · frameworks · iso 31000:2018

Who it applies to

ISO 31000 applies to any organization that wants to manage risk systematically and consistently, across any type of risk, not just cybersecurity.

What the framework requires

ISO 31000 isn’t certified: it offers principles, a framework and a risk-management process (establish context, assess, treat, monitor and communicate) that adapts to any organization.

Principles

Eight principles that guide effective management.

Framework

Leadership, integration, design and improvement.

Process

Context, assessment, treatment and monitoring.

Integration

Risk is integrated into decision-making.

Risks of not acting

  • Managing risk inconsistently across areas.
  • Deciding without formally considering risk.
  • Not monitoring or communicating the key risks.
  • Reacting to events instead of anticipating them.

The i-Prot proposal

We adopt ISO 31000 as a risk-management framework: we define principles, risk governance and a repeatable process, integrated into decision-making and the CGF cycle.

How we work with this framework

Context

Objectives, scope and risk criteria.

Identification

Risks and their sources.

Analysis and evaluation

Likelihood, impact and prioritization.

Treatment

Treatment options and plans.

Monitoring and communication

Follow-up, review and reporting.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses ISO 31000 as a source of requirements. This framework mainly covers the Assess, Prioritize, Operate & measure, and Improve stages of the cycle.

See the CGF methodology →

Complyze and ISO 31000

Complyze materializes the ISO 31000 process: risk register, treatment and indicators, with traceability over time.

Frequently asked questions

Want to manage risk with ISO 31000?

Tell us your context and we’ll define the risk-management framework and process.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.