Risk Workbook: ID Description Affected CI Category Found by Date Found Probability

Download as xls, pdf, or txt
Download as xls, pdf, or txt
You are on page 1of 5

Risk Workbook

Updated: MM/DD/YYYY

ID 1 2 3 4 5

Description This is a sample risk Data center fire Virus on fileserver X Firewall breach Due to open port Default passwords on AS400a1

Affected CI 00-000-1234 10-001-0001 20-010-0123 20-020-0022 20-020-0001

Category IT IT IT IT IT

Found by Bob Tom Sara Bob Greg

Date Found 11/02/04 01/10/05 01/10/05 01/10/05 02/15/05

Probability 3 2 4 4 3

Probability Use 1-5 scale but be sure to define it 1 Could happen in the next year but very unlikely 2 Could happen in the next year and has 25% odds 3 Could happen in the next year and has 50% odds 4 Could happen in the next year and has 75% odds 5 This will happen in the next year You will need to define the scales for each of the four impact areas. The provided scales are for reference only. Impact to Strategy Use 1-5 scale but be sure to define it Will cause minor disruption to a supporting objective. Will cause a major disruption to a supporting objective A key objective will be minorly disrupted, but within the risk tolerance. A key objective will be majorly disrupted and move outside the risk tolerance. A key objective will not be remotely obtained. Impact to Operations Use 1-5 scale but be sure to define it Will cause minor disruption to a department and/or cost less than $10,000 Will disrupt a department for up to 8 hours and/or cost up to $50,000 Will disrupt a facility for up to 8 hours and/or cost up to $75,000 Will disrupt a facility for an unknown period of time and/or cost up to $100,000 Will disrupt business and/or cost at least $150,000

1 2 3 4 5

1 2 3 4 5

0.25

Weights for each objective area 0.25 0.25 0.25 Compliance 5 5 3 4 4 Inherent Impact 4.25 4.50 3.00 3.50 3.25 Inherent % Risk Mitigated Score 12.75 9.00 12.00 14.00 9.75 20% 40% 50% 0% 50% Residual Impact 3.40 2.70 1.50 3.50 1.63

Strategic Operations Reporting 2 3 2 2 2 5 5 4 4 3 5 5 3 4 4

Impact to Reporting Use 1-5 scale but be sure to define it 1 Will cause minor disruption to reports 2 Will cause a disruption to reports but can be recovered. 3 Will cause a major disruption to reports 4 Will disrupt reporting and take significant effort to recover. 5 Will halt reporting and trigger an investigation. Impact to Compliance Use 1-5 scale but be sure to define it 1 Will cause a minor compliance issue but not a deficiency. 2 Will cause a deficiency. 3 May cause a deficiency and trigger disclosure 4 May cause a significant deficiency and trigger disclosure 5 Will cause a material weakness and trigger disclosure

Residual Last Risk Updated Score 10.20 5.40 6.00 14.00 4.88 11/02/04 02/15/05 02/10/05 01/10/05 03/10/05

By George Ed Ed George Ed

Notes. Bob implemented X to reduce the risk Updated detection and suppression Installed antivirus on fileserver X Need to see why port is open Half of default passwords fixed

"Risk" 4.00

3.50

3.00

Residual Risk Score

2.50

2.00

1.50

1.00

0.50

0 0.5 1 1.5 2 Probability 2.5 3

"Risk"

3.5

4.5

You might also like