GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-005 Risk Assessment

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Information security risks are identified and assessed on a defined schedule and when significant changes occur. Risk assessments document threats, vulnerabilities, likelihood, impact, and current controls, and results are used to prioritise treatment decisions.

Rationale

A repeatable risk assessment process is the mechanism by which an organisation identifies where its security investment should be directed. Without documented risk assessments, control selection is arbitrary.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(1)(ii)(A) is the most enforced specification in the rule and the one a healthcare customer asks for by name. Two things change for GOV-005 here: its scope has to be demonstrably every system holding electronic protected health information, and 164.306(b)(2) makes the entity's size and capabilities, its technical infrastructure and the cost of a measure recorded inputs to the choice of treatment, which GOV-005 does not currently name.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 2.1.2 fixes the process: a stated methodology, a risk tolerance level set against the risk appetite, maintained risk criteria, an all-hazards identification that reaches third parties and single points of failure, and cyber threat intelligence as an input to the analysis. Point 2.1.4 sets the review floor at at least annually and adds significant incidents as a trigger.

Framework Mappings (18)

GRC-02Risk Management Programinformative
MDS-06Adversarial Attack Analysisinformative
GRC-02Risk Management Programpartial
GDPR-Art.32.2Risk-Based Security Assessmentpartial
HIPAA-164.306.aGeneral Requirementsinformative
HIPAA-164.306.bFlexibility of Approachpartial
HIPAA-164.308.a.1.ii.ARisk Analysisfull
HIPAA-164.308.a.1.ii.BRisk Managementinformative
5.1Policies for information securityinformative
NIS2-Art.21.1Appropriate and Proportionate Cybersecurity Risk-Management Measuresinformative
NIS2-Art.21.2.aPolicies on Risk Analysis and Information System Securityinformative
NIS2-CIR-13.2Protection Against Physical and Environmental Threatsinformative
NIS2-CIR-13.3Perimeter and Physical Access Controlinformative
NIS2-CIR-2.1Risk Management Frameworkpartial
NIS2-CIR-Art.2.2Proportionality and Documented Reasoning for Non-Applicationinformative
RA-3Risk Assessmentfull
CC3.2COSO Principle 7: Identifies and Analyzes Riskfull
CC3.4COSO Principle 9: Identifies and Analyzes Significant Changepartial

Evidence (2)

reportdocumentmanual

Completed risk assessment report documenting threats, vulnerabilities, likelihood, impact ratings, and current controls for in-scope information assets.

Example: Annual Information Security Risk Assessment Report (Google Drive / SharePoint), dated within the last 12 months, showing a named assessor, risk register extract, and treatment recommendations.

Test: Request the most recent risk assessment report. Verify: (1) the report is dated within the defined assessment interval, (2) it documents threats, vulnerabilities, likelihood, and impact for each assessed asset or domain, (3) current controls are noted against each risk, (4) treatment decisions (accept/mitigate/transfer/avoid) are recorded, (5) a named assessor is identified.

system_exporttechnicalautomated

Risk register showing current risk inventory with likelihood, impact, and treatment status populated.

Example: Risk register (ISMS tool, spreadsheet, or GRC platform such as Vanta/Drata), with columns for risk ID, description, likelihood, impact, treatment decision, owner, and current status, reviewed within the last 12 months.

Test: Query or export the risk register. Verify: (1) risks identified in the most recent assessment are present, (2) each risk has a named owner, (3) treatment status is populated and current, (4) the register shows a last-reviewed date within the defined interval.

Questions (3)

boolean

Does your organisation conduct formal information security risk assessments on a defined schedule?

A risk assessment should document threats, vulnerabilities, likelihood, impact, current controls, and treatment decisions, produced by a named assessor.

select

How often is a full information security risk assessment conducted?

At least annually and when significant changes occurAnnually on a fixed schedule onlyEvery 2 yearsOnly when triggered by an incident or audit findingNo formal risk assessment process exists

Most frameworks require annual assessment at minimum, plus ad hoc assessment on significant system or business changes.

multi

Which of the following does your risk register record for each identified risk?

A likelihood ratingAn impact ratingThe treatment decision takenA named ownerThe current treatment statusThe date the entry was last reviewedNone of the above

Options run from the most commonly held to the least. A register carrying ratings but no owner cannot be worked. One carrying no review date cannot be shown to reflect the risks as they stand rather than as they stood at the last assessment.