The article presents the subject of the information security management system (ISMS) and it concentrates on the key aspect – the methods of estimating the risk. There are the risk, assessing the risk and risk management definitions in the first part The review of the methods of estimating the risk was executed then. The selection of the method, to find the most adequate to the organization is the main problem in practical aspect of designing and implementing ISMS. It is really basis to designing solutions and controls to protect information in a system way