Today, the methods of risk assessment (RA) of security information system resources (ISR) have been developed, which are not used in a single methodological basis in the context of research strategy in the field of risk management and the effective construction of appropriate information security systems. In this regard, the actual task is to develop methods for the synthesis of RA systems, taking into account these methods. On the basis of well-known studies, as well as the logical-linguistic approach, an improved methodology for the synthesis of adaptive RA systems of security (ISR), which contains ten stages, is proposed. It, through the introduction of additional stages (base parameters definition, selection of databases threats/vulnerabilities and ISR, formation of standards, a choice of terms transformation method, verification of linguistic variables), allows to formalize the creation process of adaptive tools with flexibility for processing the specified sets of values required for RA of security ISR.