Back to templates
    Template

    Scenario library

    The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.

    Risk5 Sept 20263 min read

    ISO/IEC 27001:2022ISO/IEC 27005:2022
    On this page
    Download the template

    scenario-library.xlsx · 11 kBLicensed CC BY 4.0

    What this is

    The set of risk scenarios an organisation assesses each cycle, kept alive rather than rebuilt before each audit. One sheet holds the risk sources and what the deliberate ones want, one the scenarios, scored and owned, and one the events that pull a review forward. It is deliberately not a register: it carries no acceptance decision, only a register ID pointing at the row that does.

    How to use it

    1. Say which approach this cycle used, on the Read first sheet. Identification starts from risk sources and events, or from assets and weaknesses; both can describe the same scenario 1. See 3.2.
    2. Fill Sources before Scenarios. Risk sources are human, environmental or technical, and a human source may act without intent 2. Attackers alone answer no all-hazards question.
    3. Write a desired end state only for deliberate sources — the situation that source wants to reach, which is how the informative annex expresses motivation 3. Otherwise write not applicable, and why.
    4. Write fifteen to forty scenarios, each naming a source, an event, the activities affected, the assets, the consequence type and the objective. See 3.4.
    5. Name an owner on every row while the scenario is still being written; the owner holds both the accountability and the authority 4.
    6. Score consequence, then likelihood, then read the level. All three use the scales in risk-criteria-and-appetite.xlsx; the level comes off its Matrix sheet. It is the level with existing controls in place: the register's residual level. See 3.5 to 3.7.
    7. Fill the basis column with a dated record, sector report or test result.
    8. Set the treatment option, then hand the row to the register. The four closed values are the option names printed at clause 8.2: risk avoidance, risk modification, risk retention and risk sharing 5.
    9. Keep the Events log current. Retained scenarios become monitoring scenarios, built from the factors that show one starting 6. See 3.10.

    Delete the nine example rows first. Each is invented and prefixed EXAMPLE - delete.

    What good looks like

    Six of the eighteen Scenarios columns, from one example.

    Scenario IDEventConsequenceLikelihoodLevelRegister ID
    SCN-002An engineer changes a production access rule without review, and a control recorded as implemented stops running3. Moderate4. LikelyHighR-007

    Fields

    FieldRequiredMeaningCommon mistake
    EventyesWhat happens, in one testable sentenceA missing control written as an event
    Consequence typeyesOne of the six criteria dimensions, numberedTwo dimensions in one cell, so nothing sets the level
    Basis for the likelihoodyesThe dated record, report or test behind the bandLeft blank, turning the band into a show of hands
    LevelyesRead off the criteria workbook's Matrix sheetDerived by multiplying consequence by likelihood
    Treatment optionyes when outside appetiteOne of the four names printed at clause 8.2A fifth value invented to avoid choosing
    Register IDyes when treatedThe register row holding the decision, approver and dateAn acceptance recorded here instead of in the register

    Download

    • File: scenario-library.xlsx (xlsx, 11 KB) — four sheets: Read first, Sources, Scenarios, Events log.
    • Markdown variant: content/templates/assets/_scenario-library.md, same tables.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.

    References

    1. ISO/IEC. Guidance on managing information security risks. ISO/IEC 27005:2022, licensed copy 7
    2. ISO/IEC. Information security management systems. ISO/IEC 27001:2022 8

    Annex A of ISO/IEC 27005:2022 is informative. Scenario counts and review rhythms are organisational choices, not requirements of either standard.

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC or any other standards body.

    Sources

    1. 1ISO/IEC 27005:2022 clause 7.2.1, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 27005:2022 clause 3.1.6, licensed copy · verified 2026-09-05
    3. 3ISO/IEC 27005:2022 clause A.2.3, licensed copy · verified 2026-09-05
    4. 4ISO/IEC 27005:2022 clause 7.2.2, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 27005:2022 clause 8.2, licensed copy · verified 2026-09-05
    6. 6ISO/IEC 27005:2022 clauses 10.5.1 and A.2.7, licensed copy · verified 2026-09-05
    7. 7ISO/IEC 27005:2022 clauses 3.1.6, 7.2.1, 7.2.2, 8.2, A.2.3 and A.2.7, licensed copy · verified 2026-09-05
    8. 8ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03