Back to templates
    Template

    One-page risk picture

    A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.

    Governance5 Sept 20263 min read

    ISO/IEC 27001:2022
    On this page
    Download the template

    one-page-risk-picture.xlsx · 10 kBLicensed CC BY 4.0

    What this is

    The page a board or executive committee decides from. One sheet holds five to seven risks, each with an owner role, a position against appetite, a trend and the decision requested. Two supporting sheets hold the measures behind the page and the decisions taken across cycles. It is the artefact produced by section 3.5 of Board and management reporting for security, and it answers one question: what does this body have to decide today?

    How to use it

    1. Delete the example rows. Every one is invented and prefixed EXAMPLE - delete.
    2. Select five to seven rows from the register. Choose on materiality and movement, not on score alone. See the playbook, section 3.3.
    3. Write each risk as source, event and consequence. The analysis stays in the risk register; this sheet carries the summary.
    4. Set the position against appetite from the approved criteria. Clause 6.1.2 is titled "Information security risk assessment" 1. The column is a closed list: 1. Within, 2. At, 3. Beyond.
    5. Attach a decision to every row beyond appetite. Either a funded treatment or a dated acceptance, under clause 6.1.3, "Information security risk treatment" 2. See the playbook, section 3.3.
    6. Fill the Metrics sheet with measures that force decisions. Clause 9.1 is titled "Monitoring, measurement, analysis and evaluation" 3. See the playbook, section 3.4.
    7. File the page as a management review input, at clause 9.3.2, and record the results at clause 9.3.3 4 5. See the playbook, section 3.6.
    8. Carry every open decision forward in the Decision log until it closes on evidence. See the playbook, section 3.7.

    What good looks like

    Six of the ten columns, from the rows shipped in the workbook.

    IDPosition against appetiteTrendOwner (role)Decision requestedDecision taken
    R-0013. Beyond3. WorseningHead of platform engineeringFund automated deprovisioning, or accept with a named expiry
    R-0022. At2. StableHead of customer operationsApprove the budget to cost and test an exit route
    R-0031. Within1. ImprovingHead of infrastructureNone this cycle; reported for informationNoted, with quarterly restore tests confirmed

    Fields

    FieldRequiredMeaningCommon mistake
    Risk statementyesSource, event and consequence in one sentenceNaming a missing control instead of a risk
    Business impactyesWhat the organisation losesRestating the technical failure
    Position against appetiteyesWithin, at or beyond the approved appetiteA score where no criteria were approved
    TrendyesDirection since the last cycleLeaving it blank on rows that did not move
    Owner (role)yesThe role accountable, never a personThe security function standing in for the owner
    Decision requestedyes beyond appetiteThe choice put to the body, with its optionsAn update dressed as a decision
    Decision taken, Dateyes to closeWhat the body decided, and whenA decision recorded with no date and no deciding role

    Rows whose decision follows a nonconformity close under clause 10.2, "Nonconformity and corrective action" 6.

    Download

    • File: one-page-risk-picture.xlsx (xlsx, 10 KB) — sheets Read first, Risk picture, Metrics and Decision log.
    • Markdown variant: the same tables in plain markdown, at content/templates/assets/_one-page-risk-picture.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.

    References

    1. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 7

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
    3. 3ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    4. 4ISO/IEC 27001:2022 clause 9.3.2, iso.org/obp · verified 2026-09-03
    5. 5ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
    6. 6ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    7. 7ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03