Risk assessment is at the heart of risk management, and the two together form the core competences of information security management. This title is a guide to the ISO27001 risk assessment, designed to assist asset owners and others who are working within an ISO27001/ISO17799 framework to deliver a qualitative risk assessment. It conforms with the guidance provided in BS7799-3:2006 and NIST SP 800-30.