Frameworks · ISO 31000:2018
ISO 31000: manage risk with clear principles and a clear process.
We adopt ISO 31000:2018 to give your organization a risk-management framework — of principles and process, not certifiable, but the foundation of everything.
Who it applies to
ISO 31000 applies to any organization that wants to manage risk systematically and consistently, across any type of risk, not just cybersecurity.
What the framework requires
ISO 31000 isn’t certified: it offers principles, a framework and a risk-management process (establish context, assess, treat, monitor and communicate) that adapts to any organization.
Principles
Framework
Process
Integration
Risks of not acting
- Managing risk inconsistently across areas.
- Deciding without formally considering risk.
- Not monitoring or communicating the key risks.
- Reacting to events instead of anticipating them.
The i-Prot proposal
We adopt ISO 31000 as a risk-management framework: we define principles, risk governance and a repeatable process, integrated into decision-making and the CGF cycle.
How we work with this framework
Context
Identification
Analysis and evaluation
Treatment
Monitoring and communication
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses ISO 31000 as a source of requirements. This framework mainly covers the Assess, Prioritize, Operate & measure, and Improve stages of the cycle.
See the CGF methodology →
Complyze and ISO 31000
Complyze materializes the ISO 31000 process: risk register, treatment and indicators, with traceability over time.
Frequently asked questions
Want to manage risk with ISO 31000?
Tell us your context and we’ll define the risk-management framework and process.
By submitting you accept our privacy policy.