ISO/IEC 27001:2022 Risk Assessment and Statement of Applicability
Portfolio Project 1 of 8 · 17 pages · July 2026
A complete, audit-ready ISO/IEC 27001:2022 risk assessment and Statement of Applicability for Stark Industries Inc., a fictional SaaS marketing platform hosted on AWS. Covers Clauses 6.1.2 and 6.1.3 in full: five-asset inventory with CIA ratings, five risk scenarios scored on a 5×5 likelihood-impact scale, a risk treatment plan with selected Annex A controls, and a full 93-control SoA with applicability justifications and exclusion rationale. Residual risk is scored post-treatment and presented for management sign-off.
- Five-asset ISMS scope with CIA classification (source code, AWS EC2, CI/CD, endpoint, data)
- Risk register: 5 scenarios scored L×I — 3 High, 2 Medium
- Risk treatment plan with Annex A control mapping per risk
- Full 93-control Statement of Applicability: 65 applicable, 28 excluded with justification