Risk Workbook: ID Description Affected CI Category Found by Date Found Probability
Risk Workbook: ID Description Affected CI Category Found by Date Found Probability
Risk Workbook: ID Description Affected CI Category Found by Date Found Probability
Updated: MM/DD/YYYY
ID 1 2 3 4 5
Description This is a sample risk Data center fire Virus on fileserver X Firewall breach Due to open port Default passwords on AS400a1
Category IT IT IT IT IT
Probability 3 2 4 4 3
Probability Use 1-5 scale but be sure to define it 1 Could happen in the next year but very unlikely 2 Could happen in the next year and has 25% odds 3 Could happen in the next year and has 50% odds 4 Could happen in the next year and has 75% odds 5 This will happen in the next year You will need to define the scales for each of the four impact areas. The provided scales are for reference only. Impact to Strategy Use 1-5 scale but be sure to define it Will cause minor disruption to a supporting objective. Will cause a major disruption to a supporting objective A key objective will be minorly disrupted, but within the risk tolerance. A key objective will be majorly disrupted and move outside the risk tolerance. A key objective will not be remotely obtained. Impact to Operations Use 1-5 scale but be sure to define it Will cause minor disruption to a department and/or cost less than $10,000 Will disrupt a department for up to 8 hours and/or cost up to $50,000 Will disrupt a facility for up to 8 hours and/or cost up to $75,000 Will disrupt a facility for an unknown period of time and/or cost up to $100,000 Will disrupt business and/or cost at least $150,000
1 2 3 4 5
1 2 3 4 5
0.25
Weights for each objective area 0.25 0.25 0.25 Compliance 5 5 3 4 4 Inherent Impact 4.25 4.50 3.00 3.50 3.25 Inherent % Risk Mitigated Score 12.75 9.00 12.00 14.00 9.75 20% 40% 50% 0% 50% Residual Impact 3.40 2.70 1.50 3.50 1.63
Impact to Reporting Use 1-5 scale but be sure to define it 1 Will cause minor disruption to reports 2 Will cause a disruption to reports but can be recovered. 3 Will cause a major disruption to reports 4 Will disrupt reporting and take significant effort to recover. 5 Will halt reporting and trigger an investigation. Impact to Compliance Use 1-5 scale but be sure to define it 1 Will cause a minor compliance issue but not a deficiency. 2 Will cause a deficiency. 3 May cause a deficiency and trigger disclosure 4 May cause a significant deficiency and trigger disclosure 5 Will cause a material weakness and trigger disclosure
Residual Last Risk Updated Score 10.20 5.40 6.00 14.00 4.88 11/02/04 02/15/05 02/10/05 01/10/05 03/10/05
By George Ed Ed George Ed
Notes. Bob implemented X to reduce the risk Updated detection and suppression Installed antivirus on fileserver X Need to see why port is open Half of default passwords fixed
"Risk" 4.00
3.50
3.00
2.50
2.00
1.50
1.00
0.50
"Risk"
3.5
4.5