AHP Learning Works Pvt Ltd
Risk Assessment & Treatment Procedure
S. No Version Date of Change Revision History
1 1.0 11/1/2022 First Release
Prepared By: PBC Approved By: CISO
Confidentiality
Score Label
1 Public
2 Internal
Company
3 Confidential
Integrity
Score Label
1 Low
2 Medium
3 High
Availability
Score Label
1 Low
2 Medium
3 High
The highest score of C, I, A value is taken as the Asset Value (AV)
Identification of Vulnerabilities - Vulnerability rating is given on a scale of 1 to 3
Score Label
1 Low
2 Medium
3 High
Identification of Threat
The threat value is calculated as the combination of Impact and Probability
Impact - The Impact value is rated on a scale of 1 to 3
Score Label
1 Low
2 Medium
3 High
Probability - The probability value is rated on a scale of 1 to 3
Score Label
1 Low
2 Medium
3 High
Threat value calculation formula:
Formula Threat value
Impact*Probability < 3 1
3 <= Impact*Probability < 5 2
Impact*Probability >= 5 3
Risk Determination
Formula for Risk Value = (Asset value * Vulnerability Value * Threat Value)
Risk Value Matrix
Threat
Vulnerability
1
2
Asset Value 3
4
5
Description
The Information which is not confidential and can be public without any
implications for company. Loss of availability due to system downtime is
an acceptable risk. Integrity is important but not vital.
Non-sensitive information restricted to internal use only
Information collected and used by Company in the conduct of its business
to employ people, to log and fulfill client orders, and to manage all aspects
of corporate finance.
Description
The unauthorized damage or modification of information is not critical to
business applications and business impact is negligible
(90-95% error free)
The unauthorized damage or modification of information is important to
business applications and business impact is significant
(96-99% error free.)
The unauthorized damage or modification of information is critical to
business applications and business impact is major.
(100% error free)
Description
No interruption of access beyond 7 days.
No interruption of access beyond 1 day.
No interruption beyond 0.5 days.
s taken as the Asset Value (AV)
Vulnerability rating is given on a scale of 1 to 3
Description
Very Secure
Security is present but needs to improve
Security is clearly inadequate at present and needs to improve strongly
he combination of Impact and Probability
t - The Impact value is rated on a scale of 1 to 3
Description
Low business process impact
Medium business process impact
High business process impact
y - The probability value is rated on a scale of 1 to 3
Description
Unlikely or impossible
Security control is present but might be exploited
Easy to exploit or no security control in place
alue * Vulnerability Value * Threat Value)
1 2
1 2 3 1
1 2 3 2
2 4 6 4
3 6 9 6
4 8 12 8
5 10 15 10
2 3
2 3 1 2 3
4 6 3 6 9
8 12 6 12 18
12 18 9 18 27
16 24 12 24 36
20 30 15 30 45