ISO 27001:2022-Compliant Cybersecurity: Getting Started
with Marc Menninger
Key:
CIA: L = Low; M = Medium; H = High
Impact: 1 = Minor; 2 = Moderate; 3 = Catastrophic
Likelihood: 1 = Unlikely; 2 = Possible; 3 = Likely
Threat Description Vulnerability Description
Affected Assets, (Things that can harm (An exposure in an information system,
Resources, or Processes assets/resources/processes) procedure, or control that could be exploited)
Suggested keys
Confidentiality
Confidentiality Level Confidentiality Definition
High Information which is very sensitive or
private, of highest value to the
organization and intended to use by
named individuals only. The
unauthorized disclosure of such
information can cause severe harm
(e.g. Legal or financial liability, adverse
competitive impact, loss of brand
name). E.g. Merger and Acquisition
related information, Marketing
strategy, etc.
Medium Information belonging to the
organization and not for disclosure to
public or external parties. The
unauthorized disclosure of information
here can cause a limited harm to the
organization. e.g. Organization Charts,
Internal Telephone Directory.
Low Non-sensitive information available for
public disclosure. The impact of
unauthorized disclosure of such
information shall not harm the
organization in any way. E.g. Press
releases, organization newsletters,
information published on
organization’s public website, etc.
Integrity
Integrity Requirement Integrity Definition
High Integrity degradation is unacceptable.
Medium There is significant impact on the
organization if the accuracy and
completeness of data is degraded.
Low There is minimal impact on the
organization if the accuracy and
completeness of data is degraded.
Availability
Availability Requirement Availability Definition
High The asset / information is required on
24x7 basis
Medium There is significant impact on the
organization if the asset / information
is not available for up to 24 hours.
Low There is minimal impact on the
organization if the asset / information
is not available for up to 48 hours.
arted
Risk Register
Risk Treatment:
M = Risk Reduction/Mitigation; A = Risk Acceptance; Av = Risk Avoidance; T = Risk Transfer
Impact Description
(The business consequences of Confidentiality Integrity Availability
a successful exploit) Risk Owner (L, M, H) (L, M, H) (L, M, H) Impact (1–3)
Risk Level Matrix
Catastrophic(3) Low (3) Medium (6) High (9)
act
Moderate (2) Low (2) Medium (6) Medium (6)
Impact
Minor (1) Low (1) Low (2) Low (3)
Unlikely (1) Possible (2) Likely (3)
Likelihood
Risk Score = Impact x Likelihood
Residual Risk = Risk Remaining after Controls (Risk Treatment) Have Been Implemented
Risk Treatment Risk Treatment Residual Risk (1– Residual Risk
Likelihood (1–3) Risk Score (1–9) Required? (Y/N) (M, A, Av, T) 9) Accepted
Risk Treatment Recommendations
Risk Treatment Risk Treatment Definition Key
Risk The level of risk should
reduction/mitigatio be reduced through the
n selection of controls so
that the residual risk can
be re-assessed as being
M
acceptable.
Risk acceptance If the level of risk meets
the risk acceptance
criteria, there is no need
for implementing A
additional controls and
the risk can be retained.
Risk avoidance The activity or condition
that gives rise to the
particular risk should be
avoided by withdrawing
from an activity or Av
changing the conditions
under which the activity
is operated.
Risk transfer Transfer the risk to
another entity (such as by T
contract or insurance).