Risk management is often described as the heart of an information security management system. In the context of ISO 27001, this statement is not merely figurative — it is structural. Yet many organisations continue to associate risk management solely with the certification…