The Risk Assessment is the foundation of an organisation’s Information Security Management System. As well as being a mandatory component required by ISO 27001 it is the best way of determining what the rest of the management system needs to contain.