Skip to main content
Category: Risk Assessment and Treatment

Impact

Simply put

Impact refers to the effect or consequence that a risk event would have on an organization if it occurred. In general usage it means a marked effect or influence on a particular entity or environment. The provided evidence defines the term only in general and non-security contexts, so a framework-specific definition cannot be reliably established from these sources.

Formal definition

In risk management terminology, impact denotes the magnitude of consequence resulting from a threat exploiting a vulnerability, and is typically assessed alongside likelihood to determine risk level. However, the evidence packet supplied contains only general-language and unrelated commercial definitions of "impact" (for example, a marked effect or influence, or the force of one object hitting another) and no material addressing its use within SOC 2 or ISO/IEC 27001. A precise, framework-aligned technical definition cannot be substantiated from the available sources; practitioners should treat impact assessment methodology as dependent on the organization's chosen risk assessment approach and scope.

Why it matters

In risk management, impact is one of the two core dimensions, alongside likelihood, that practitioners use to size a risk and prioritize how to treat it. Understanding the potential consequence of a risk event helps organizations decide where to direct limited security resources, which controls to strengthen, and which risks to accept, mitigate, transfer, or avoid. Without a defensible sense of impact, risk registers become lists of hazards with no basis for ranking them.

Both SOC 2 and ISO/IEC 27001 environments rely on risk assessment as a foundation for control selection, so how an organization characterizes impact directly shapes its scope and its Statement of Applicability (in the ISO 27001 case) or its selection of Trust Services Criteria and supporting controls (in the SOC 2 case). It is important to note, however, that the evidence supplied for this entry defines "impact" only in general-language and unrelated commercial contexts, for example, a marked effect or influence on an entity or environment, or the force of one object striking another. A framework-specific, security-aligned definition cannot be reliably established from these sources.

Because impact assessment methodology depends heavily on an organization's chosen risk approach, scope, and the judgment of its assessors, practitioners should avoid treating any single impact scale or scoring method as universally mandatory. The magnitude of a consequence is context-dependent, and the same event may carry very different impact ratings across organizations with different assets, obligations, and risk tolerances.

Who it's relevant to

GRC and Risk Managers
Risk professionals use impact ratings to prioritize risks and justify control decisions within a risk register. Because the supplied evidence does not define impact in a framework-specific way, these practitioners should rely on their organization's documented risk assessment methodology to determine how impact is scaled and applied.
ISO 27001 Practitioners
Those maintaining an ISMS use impact as part of the risk assessment that informs control selection and the Statement of Applicability. The magnitude of consequence assigned to a given risk depends on organizational scope and assessment approach, not on a fixed impact scale.
SOC 2 Compliance Teams and Auditors
Teams preparing for or performing a SOC 2 examination consider impact when assessing risks tied to the selected Trust Services Criteria. How impact is characterized varies by engagement scope and by the organization's risk approach, and this entry's sources do not provide a SOC 2-specific definition.

Inside Impact

Impact (definition)
The magnitude of harm or consequence that could result if a risk materializes, typically expressed in terms of the effect on confidentiality, integrity, or availability of information or systems, or on business objectives, finances, reputation, or legal and regulatory standing.
Impact in risk assessment
Within an ISO/IEC 27001 ISMS, impact is one of the two dimensions, alongside likelihood, typically combined during risk assessment to determine the level of a risk. The risk assessment then informs the selection of Annex A reference controls documented in the Statement of Applicability.
Impact scales and criteria
Organizations generally define impact using qualitative, quantitative, or hybrid scales (for example, low/medium/high or monetary ranges). The specific scale and thresholds are set by the organization's risk criteria rather than prescribed by the standard, and they vary depending on scope and context.
Impact in a SOC 2 context
In a SOC 2 examination, considerations of potential impact typically inform how a service organization designs controls to address the Trust Services Criteria (with Security, the Common Criteria, required and other categories optional based on scope). Impact assessment supports control design but is evaluated by the CPA firm only within the controls and period covered by the report.
Relationship to residual risk
Impact contributes to inherent risk before controls and to residual risk after controls are applied. Reducing impact (for example, through segmentation, encryption, or backups) is one way, alongside reducing likelihood, that controls may lower a risk to within an organization's risk acceptance criteria.

Common questions

Answers to the questions practitioners most commonly ask about Impact.

Is the impact rating in a risk assessment a fixed value defined by the SOC 2 or ISO 27001 standards?
No. Neither framework prescribes a universal impact scale or fixed values. In ISO 27001, impact is a component of the risk assessment methodology that the organization defines under clauses 4 through 10, and the criteria are typically set by the organization based on its context. In a SOC 2 examination, impact considerations inform how controls are scoped against the Trust Services Criteria, but the specific ratings depend on the organization's own methodology and the auditor's evaluation. Any impact scale you adopt is a scoping decision rather than a mandated value.
Does assessing impact under one framework mean the impact analysis satisfies the other framework?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but partial. An ISO 27001 impact analysis feeds the risk assessment that informs the Statement of Applicability and Annex A control selection, while impact considerations in a SOC 2 engagement relate to how controls address the applicable Trust Services Criteria over the covered period or point in time. The two use different structures and objectives, so an impact analysis performed for one does not, on its own, demonstrate conformance for the other.
How is impact typically combined with likelihood in an ISO 27001 risk assessment?
In most ISMS implementations, impact and likelihood are evaluated together to derive a risk level, which then informs risk treatment decisions and Annex A control selection recorded in the Statement of Applicability. The specific method, qualitative, quantitative, or a matrix approach, is defined by the organization within the requirements of clauses 4 through 10. The standard does not mandate a single formula, so the pairing of impact and likelihood depends on the methodology you document and apply consistently.
What dimensions of impact should we consider when scoping a risk assessment?
Organizations typically consider impact across dimensions such as confidentiality, integrity, and availability, and may extend to operational, financial, legal, regulatory, or reputational consequences depending on scope. The relevant dimensions depend on the organization's context, the assets in scope, and applicable requirements. Because the frameworks do not fix a required set of dimensions, document which ones you assess and why, so the rationale is defensible during audit or certification activities.
How should impact assessments be documented for a SOC 2 examination versus an ISO 27001 certification?
For ISO 27001, impact assessments are generally documented as part of the risk assessment and treatment records that support the Statement of Applicability, which an accredited certification body reviews against the ISMS requirements. For a SOC 2 examination, impact considerations are reflected in how controls are described and scoped against the applicable Trust Services Criteria, and the licensed CPA firm evaluates that evidence within the report's defined boundaries. The documentation expectations differ, so retain records aligned to each framework's evaluation approach rather than assuming one format serves both.
How often should impact ratings be reviewed?
Review frequency is a scoping decision rather than a fixed rule. In most ISMS implementations, impact ratings are revisited as part of ongoing risk assessment activities, when significant changes occur, or on a defined periodic basis set by the organization. For a SOC 2 Type II, the relevant consideration is that controls and their supporting analysis remain effective throughout the review period, whose length is set by scoping decisions. In both cases, aligning review cadence with changes in your environment and applicable requirements is typically expected.

Common misconceptions

Impact and likelihood are the same thing, or impact alone determines a risk's rating.
Impact measures the consequence if a risk occurs, while likelihood measures the probability of occurrence. In most risk assessments the two are considered together to derive the overall risk level; impact by itself does not fully rank a risk.
There is a single, standardized impact scale that all SOC 2 and ISO 27001 assessments must use.
Neither framework mandates a fixed impact scale. ISO/IEC 27001 requires that risk criteria be defined but leaves the specific scale to the organization, and SOC 2 evaluates the controls a service organization designs. Scales and thresholds vary by scope, context, and the decisions of the organization, auditor, or certification body.
A low impact rating, or a favorable SOC 2 report or ISO 27001 certificate, means an incident cannot cause harm.
A low impact rating reflects an estimate under defined criteria, not a guarantee. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined ISMS scope; neither eliminates the possibility of high-consequence events outside those boundaries.

Best practices

Define clear, documented impact criteria and scales as part of your risk criteria before conducting assessments, so that ratings are consistent and repeatable across the organization.
Consider impact across multiple dimensions, confidentiality, integrity, availability, financial, legal and regulatory, and reputational, rather than relying on a single measure.
Assess impact alongside likelihood when determining risk levels, and use the combined result to inform selection of ISO 27001 Annex A controls in the Statement of Applicability (specifying the standard version when referencing control counts, since these differ between the 2013 and 2022 editions).
Distinguish inherent impact from residual impact by documenting how specific controls are intended to reduce consequences, and re-evaluate residual risk against your acceptance criteria.
Revisit impact ratings periodically and after significant changes to systems, scope, threats, or business objectives, since impact estimates can drift as the environment evolves.
Communicate the limitations of impact ratings to stakeholders, noting that estimates reflect defined criteria and that a SOC 2 report or ISO 27001 certificate covers only the controls, period, or ISMS scope defined for the engagement.