0% found this document useful (0 votes)
55 views7 pages

ISO 27001 Risk Register Overview

The document outlines the framework for ISO 27001:2022-compliant cybersecurity, detailing the assessment of risks related to confidentiality, integrity, and availability of information. It includes a risk register, treatment options, and a risk level matrix to evaluate the impact and likelihood of threats. Additionally, it provides definitions and classifications for various levels of confidentiality, integrity, and availability requirements.

Uploaded by

sourav.dasgupta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
55 views7 pages

ISO 27001 Risk Register Overview

The document outlines the framework for ISO 27001:2022-compliant cybersecurity, detailing the assessment of risks related to confidentiality, integrity, and availability of information. It includes a risk register, treatment options, and a risk level matrix to evaluate the impact and likelihood of threats. Additionally, it provides definitions and classifications for various levels of confidentiality, integrity, and availability requirements.

Uploaded by

sourav.dasgupta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd

ISO 27001:2022-Compliant Cybersecurity: Getting Started

with Marc Menninger

Key:
CIA: L = Low; M = Medium; H = High
Impact: 1 = Minor; 2 = Moderate; 3 = Catastrophic
Likelihood: 1 = Unlikely; 2 = Possible; 3 = Likely

Threat Description Vulnerability Description


Affected Assets, (Things that can harm (An exposure in an information system,
Resources, or Processes assets/resources/processes) procedure, or control that could be exploited)

Suggested keys

Confidentiality
Confidentiality Level Confidentiality Definition
High Information which is very sensitive or
private, of highest value to the
organization and intended to use by
named individuals only. The
unauthorized disclosure of such
information can cause severe harm
(e.g. Legal or financial liability, adverse
competitive impact, loss of brand
name). E.g. Merger and Acquisition
related information, Marketing
strategy, etc.
Medium Information belonging to the
organization and not for disclosure to
public or external parties. The
unauthorized disclosure of information
here can cause a limited harm to the
organization. e.g. Organization Charts,
Internal Telephone Directory.

Low Non-sensitive information available for


public disclosure. The impact of
unauthorized disclosure of such
information shall not harm the
organization in any way. E.g. Press
releases, organization newsletters,
information published on
organization’s public website, etc.

Integrity
Integrity Requirement Integrity Definition
High Integrity degradation is unacceptable.
Medium There is significant impact on the
organization if the accuracy and
completeness of data is degraded.
Low There is minimal impact on the
organization if the accuracy and
completeness of data is degraded.

Availability
Availability Requirement Availability Definition
High The asset / information is required on
24x7 basis
Medium There is significant impact on the
organization if the asset / information
is not available for up to 24 hours.
Low There is minimal impact on the
organization if the asset / information
is not available for up to 48 hours.
arted

Risk Register

Risk Treatment:
M = Risk Reduction/Mitigation; A = Risk Acceptance; Av = Risk Avoidance; T = Risk Transfer

Impact Description
(The business consequences of Confidentiality Integrity Availability
a successful exploit) Risk Owner (L, M, H) (L, M, H) (L, M, H) Impact (1–3)

Risk Level Matrix


Catastrophic(3) Low (3) Medium (6) High (9)
act
Moderate (2) Low (2) Medium (6) Medium (6)
Impact

Minor (1) Low (1) Low (2) Low (3)

Unlikely (1) Possible (2) Likely (3)

Likelihood
Risk Score = Impact x Likelihood
Residual Risk = Risk Remaining after Controls (Risk Treatment) Have Been Implemented

Risk Treatment Risk Treatment Residual Risk (1– Residual Risk


Likelihood (1–3) Risk Score (1–9) Required? (Y/N) (M, A, Av, T) 9) Accepted

Risk Treatment Recommendations


Risk Treatment Risk Treatment Definition Key
Risk The level of risk should
reduction/mitigatio be reduced through the
n selection of controls so
that the residual risk can
be re-assessed as being
M
acceptable.

Risk acceptance If the level of risk meets


the risk acceptance
criteria, there is no need
for implementing A
additional controls and
the risk can be retained.

Risk avoidance The activity or condition


that gives rise to the
particular risk should be
avoided by withdrawing
from an activity or Av
changing the conditions
under which the activity
is operated.

Risk transfer Transfer the risk to


another entity (such as by T
contract or insurance).

You might also like