Information Security Risk Register
Holds the assessed risk population with scoring, ownership, treatment status and appetite breach flagging.
Available soon
- Format
- Excel
- Size
- 110 KB
- Length
- 11 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Register
- Appetite
- Summary
- Heat Map
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. The review flag, trigger flag and acceptance check use this date. |
| 2 | On the Appetite sheet, list your risk categories and choose each one's appetite level from your approved Cyber Risk Appetite Statement Template (Averse: appetite up to Low, tolerance up to Medium; Cautious: appetite up to Medium, tolerance up to High; Open: appetite up to High, tolerance up to High). The register reads the appetite and tolerance from there. |
| 3 | Add one row per risk (RM-11). Give it a Risk ID (R-01, R-02 …) that never changes. Write the Risk scenario as a threat, the weakness it uses, the service or asset affected and the consequence (RM-01); use the Cyber Risk Scenario Library as a starting point. Choose the Category and name one Risk owner: the executive accountable for the service it would hurt, not the security team (RM-02). |
| 4 | Score it as the Risk Assessment Methodology & Scoring Model sets out (RM-03): Inherent impact and likelihood (1–4) as if the existing controls were not there, then Existing controls in plain words, then Residual impact and likelihood with those controls working as they do today. Impact is judged on the worst consequence; likelihood over the next 12 months. Scores and bands calculate (Low 1–3, Medium 4–6, High 8–9, Critical 12–16). |
| 5 | Read the Position against appetite (RM-05). A risk outside appetite needs a treatment decision within 30 calendar days of first being assessed outside appetite; later reviews do not restart the window (RM-06): choose Reduce, Avoid, Transfer or Accept. For Reduce, Avoid or Transfer, enter the action IDs from the Risk Treatment Plan in Linked actions (RM-07). |
| 6 | For Accept, record the acceptance on the Risk Acceptance Form & Approval Record, enter its reference and review date here, and check that the right person signed: Who may accept shows the band's approvers; outside appetite, executive management signs as well; outside tolerance, the band's approvers can only recommend and only the board or its equivalent may accept (RM-08). |
| 7 | Every quarter, each owner reviews each of their risks and the date goes in Last owner review (RM-09). Before you update the scores for the new quarter, copy each Residual score into Last quarter's residual score, so Movement shows Better, Same or Worse. |
| 8 | When a trigger happens (a major incident, a major change, a new threat, an audit or test finding, or a change in law or contract), record it and its date on every risk it touches. Reassess those risks within 10 working days (RM-10) and enter the Reassessed on date; Trigger flag shows the deadline and when it has passed. |
| 9 | Clear every Record check that does not say OK. Once a year, reassess the whole register (RM-09). Take the Summary figures into the quarterly report to [[e.g. Executive Committee]] (RM-12). |
| 10 | Delete the EXAMPLE rows on the Register and Appetite sheets before the register is approved. Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: 10 to 20 risks are enough to start; one person may assess them all, but each still needs an owner outside the security role (RM-02). A quarterly review can be one meeting with the owners.
Tailoring — regulated entity (NIS2, DORA): keep a copy of the register at each quarter end (with the As-at date fixed) as the record of risk assessment. Under DORA, reassess on each major change and review the risk scenarios at least once a year (Art 8(2), 8(3)); the scoring and acceptance rules must match your ICT risk management policy (Delegated Regulation (EU) 2024/1774 Art 3). Add a column for the critical or important function a risk affects. Where personal data is involved, the residual score is part of showing security appropriate to the risk (GDPR Art 32(1)).
Tailoring — IT run by a service provider: risks in the provider's service belong in this register, owned by your executive for the service it supports. The provider can supply evidence for the existing controls; transferring part of the impact by contract does not transfer the ownership.
The scales, bands, appetite levels, treatments, acceptance authority and triggers are on the Lists sheet. If your Risk Assessment Methodology & Scoring Model sets different ones, change them there and nowhere else. The reassessment deadline (10 working days) is set on the Summary sheet.
EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30 (Q3 2026). Its 12 top risks are those in the quarterly board report: 2 outside appetite (R-01, R-02), both within tolerance; R-04 moved from 9 to 4 this quarter, after TA-04 separated the last warehouse site from the office network, and is back within appetite.
Register
One row per assessed risk (RM-11). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.
| Example | Risk ID | Category | Appetite level | Risk scenario | Risk owner | Inherent impact (1–4) | Inherent likelihood (1–4) | Inherent score | Inherent band | Existing controls | Residual impact (1–4) | Residual likelihood (1–4) | Residual score | Residual band | Last quarter's residual score | Movement | Position against appetite | Treatment | Linked actions | Who may accept | Acceptance ref | Acceptance review date | Last owner review | Reviewed this quarter | Trigger since last assessment | Trigger date | Reassessed on | Trigger flag | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | R-01 | Service availability | Cautious | Ransomware takes online ordering offline for more than 2 days | Chief Operating Officer | 4 | 3 | 12 | Critical | Nightly backups of the ordering platform; endpoint detection on servers; recovery of the whole platform not yet proven within 2 days | 4 | 2 | 8 | High | 8 | Same | Outside appetite, within tolerance | Reduce | TA-01 | Accountable executive and Head of Information Security, and executive management as well | 10 Sep 2026 | Yes | OK | Treatment action TA-01 (€180,000) is the decision put to the board; see the Risk Treatment Plan | ||||||
| EXAMPLE | R-02 | Financial fraud | Cautious | Payment fraud through a compromised supplier email account | Chief Financial Officer | 3 | 4 | 12 | Critical | Two-person approval of payments; accounts payable staff trained to spot changed bank details | 3 | 3 | 9 | High | 9 | Same | Outside appetite, within tolerance | Reduce | TA-02 | Accountable executive and Head of Information Security, and executive management as well | 8 Sep 2026 | Yes | OK | |||||||
| EXAMPLE | R-03 | Customer and personal data | Cautious | Customer data exposed through the ordering service | Chief Operating Officer | 4 | 2 | 8 | High | Web application firewall; yearly penetration test of the ordering service; customer data encrypted at rest | 4 | 1 | 4 | Medium | 4 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 22 Jul 2026 | Yes | OK | ||||||||
| EXAMPLE | R-04 | Service availability | Cautious | Ransomware spreads from warehouse office PCs to warehouse systems | Head of Logistics | 3 | 3 | 9 | High | Warehouse networks separated from the office network at all three sites (last site 2026-09-09, tested 2026-09-11); endpoint protection on office PCs | 2 | 2 | 4 | Medium | 9 | Better | Within appetite | Reduce | TA-04 | Risk owner and Head of Information Security | 30 Sep 2026 | Yes | A major incident, or a near miss that shows a risk was underrated | 12 Aug 2026 | 20 Aug 2026 | Reassessed | OK | Reassessed on 2026-08-20 after the 12 Aug 2026 ransomware incident and kept at 9: two sites were still on the office network. The last site was separated on 2026-09-09 and tested on 2026-09-11 (TA-04); the quarter-end review scored it 4 | ||
| EXAMPLE | R-05 | Service availability | Cautious | Critical weaknesses on internet-facing systems exploited before they are fixed | Head of IT | 3 | 3 | 9 | High | Monthly vulnerability scanning; patching deadlines by severity; internet-facing systems behind a web application firewall | 3 | 2 | 6 | Medium | 6 | Same | Within appetite | Reduce | TA-03 | Risk owner and Head of Information Security | 15 Sep 2026 | Yes | OK | |||||||
| EXAMPLE | R-06 | Third-party dependency | Cautious | Managed IT provider fails or is compromised | Head of IT | 3 | 2 | 6 | Medium | Contract with security and service-level clauses; provider's yearly assurance report; insurance covering provider failure | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Transfer | Risk owner | 14 Jul 2026 | Yes | OK | Transferred in part by contract and insurance; the Head of IT still owns the risk | |||||||
| EXAMPLE | R-07 | People and insider | Cautious | Administrator misuses privileged access | Head of IT | 3 | 2 | 6 | Medium | Separate administrator accounts with multi-factor authentication; administrator activity logged | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Reduce | Risk owner | 14 Jul 2026 | Yes | OK | ||||||||
| EXAMPLE | R-08 | Regulatory compliance | Averse | Significant incident not reported to the authority on time (NIS2) | Head of Information Security | 2 | 2 | 4 | Medium | Incident response procedure with the notification steps and deadlines; on-call rota | 2 | 1 | 2 | Low | 2 | Same | Within appetite | Reduce | Risk owner | 5 Aug 2026 | Yes | OK | ||||||||
| EXAMPLE | R-09 | People and insider | Cautious | Staff account taken over through phishing | HR Director | 2 | 4 | 8 | High | Multi-factor authentication on email; phishing report button; awareness training every quarter | 2 | 3 | 6 | Medium | 6 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 27 Aug 2026 | Yes | OK | ||||||||
| EXAMPLE | R-10 | Service availability | Cautious | Backups cannot restore a critical system | Head of IT | 4 | 2 | 8 | High | Daily backups with an offline copy; one critical system restored in a test each quarter | 4 | 1 | 4 | Medium | 4 | Same | Within appetite | Reduce | Risk owner and Head of Information Security | 14 Jul 2026 | Yes | OK | ||||||||
| EXAMPLE | R-11 | Customer and personal data | Cautious | Cloud storage misconfigured and customer files exposed | Head of IT | 3 | 2 | 6 | Medium | Cloud configuration baseline; monthly configuration scan | 3 | 1 | 3 | Low | 3 | Same | Within appetite | Reduce | Risk owner | 14 Jul 2026 | Yes | OK | ||||||||
| EXAMPLE | R-12 | Customer and personal data | Cautious | Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolen | Head of Logistics | 2 | 2 | 4 | Medium | Acceptance conditions: Laptops stay on site, are locked away overnight and are not used for customer data exports. | 2 | 2 | 4 | Medium | 4 | Same | Within appetite | Accept | Risk owner and Head of Information Security | RA-01 | 15 Jun 2027 | 1 Sep 2026 | Yes | OK | Accepted on 2026-06-15 by the Head of Logistics (risk owner) and Head of Information Security until the March 2027 laptop refresh (see RA-01) |
Appetite
Your risk categories and each one's appetite level, from the approved Cyber Risk Appetite Statement Template. The register reads its Appetite level from here.
| Example | Category ID | Category | Appetite level | Appetite: highest band accepted | Tolerance: highest band tolerated while treated | Approved in the risk appetite statement (date) |
|---|---|---|---|---|---|---|
| EXAMPLE | RC-01 | Service availability | Cautious | Medium | High | [[YYYY-MM-DD]] |
| EXAMPLE | RC-02 | Customer and personal data | Cautious | Medium | High | [[YYYY-MM-DD]] |
| EXAMPLE | RC-03 | Financial fraud | Cautious | Medium | High | [[YYYY-MM-DD]] |
| EXAMPLE | RC-04 | Regulatory compliance | Averse | Low | Medium | [[YYYY-MM-DD]] |
| EXAMPLE | RC-05 | Third-party dependency | Cautious | Medium | High | [[YYYY-MM-DD]] |
| EXAMPLE | RC-06 | People and insider | Cautious | Medium | High | [[YYYY-MM-DD]] |
Appetite levels
| Level | Appetite | Tolerance | What it means | ||
|---|---|---|---|---|---|
| Averse | Low | Medium | We avoid this risk and act on anything above Low. | ||
| Cautious | Medium | High | We accept some risk for a clear business benefit, with controls. | ||
| Open | High | High | We accept higher risk to pursue opportunity; Critical is never within tolerance. | ||
| Appetite is the highest residual band accepted without escalation; tolerance is the highest band tolerated while a plan brings the risk back. Critical is never within tolerance. | |||||
Summary
Register summary
Every figure is calculated from the Register as at the date shown. Use them for the quarterly report to executive management (RM-12); RMM-02 comes from the Risk Treatment Plan.
| As-at date | 30 Sep 2026 | EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY(). |
| Reassessment deadline after a trigger (working days, RM-10) | 10 | Your procedure's deadline; the rule's default is shown. |
Risks by band
| Band (score) | Now (residual) | Before controls (inherent) | Last quarter (residual) |
|---|---|---|---|
| Low (1–3) | 4 | 0 | 4 |
| Medium (4–6) | 6 | 5 | 5 |
| High (8–9) | 2 | 5 | 3 |
| Critical (12–16) | 0 | 2 | 0 |
| All risks | 12 | 12 | 12 |
Position against appetite
| Position | Risks | With a treatment decision | Worse than last quarter | |||
|---|---|---|---|---|---|---|
| Within appetite | 10 | — | — | |||
| Outside appetite, within tolerance | 2 | 2 | 0 | |||
| Outside tolerance | 0 | 0 | 0 | |||
| Overall position (the board measure) | Outside appetite, within tolerance | Outside tolerance if any risk is past its tolerance; otherwise outside appetite, within tolerance if any risk is above appetite; otherwise within appetite. | ||||
Headline measures
| Measure | Result | Target | Status | What it means | ||
|---|---|---|---|---|---|---|
| RMM-01 Risks outside appetite | 2 | Each with a treatment decision | On target | Top risks whose residual band is above their category's appetite; and of those, above its tolerance. RMM-01 target: zero past tolerance; outside appetite each with a treatment decision. | ||
| RMM-01 Of those, past tolerance | 0 | 0 | On target | A risk past tolerance goes to the board; only the board or its equivalent may accept it (RM-08). | ||
| RMM-03 Acceptances past review | 0 | 0 | On target | Accepted risks whose acceptance review date has passed. Review each on the Risk Acceptance Form & Approval Record. | ||
| RMM-04 Risks not reviewed this quarter | 0 | 0 | On target | Register entries with no owner review in the last quarter (RM-09). Counted as no owner review in the 3 months up to the as-at date. | ||
| RMM-02 Treatment actions overdue | — | Zero older than 30 days | — | From the Risk Treatment Plan. | ||
Position by category
| Category | Appetite level | Risks | Within appetite | Outside appetite, within tolerance | Outside tolerance | Category position |
|---|---|---|---|---|---|---|
| Service availability | Cautious | 4 | 3 | 1 | 0 | Outside appetite, within tolerance |
| Customer and personal data | Cautious | 3 | 3 | 0 | 0 | Within appetite |
| Financial fraud | Cautious | 1 | 0 | 1 | 0 | Outside appetite, within tolerance |
| Regulatory compliance | Averse | 1 | 1 | 0 | 0 | Within appetite |
| Third-party dependency | Cautious | 1 | 1 | 0 | 0 | Within appetite |
| People and insider | Cautious | 2 | 2 | 0 | 0 | Within appetite |
Movement, treatment and triggers
| Item | Risks |
|---|---|
| Better than last quarter | 1 |
| Same as last quarter | 11 |
| Worse than last quarter | 0 |
| New this quarter | 0 |
| Treatment: Reduce | 10 |
| Treatment: Avoid | 0 |
| Treatment: Transfer | 1 |
| Treatment: Accept | 1 |
| No treatment recorded | 0 |
| Awaiting reassessment after a trigger (RM-10) | 0 |
| of which past the deadline | 0 |
| Rows with a record check to resolve | 0 |
Quarterly review record
| Item | Entry | |||||
|---|---|---|---|---|---|---|
| Reviewed by (name, role) and date | [[Name, role, YYYY-MM-DD]] | |||||
| Risks whose score changed, and why | [[e.g. R-04 from 9 to 4: warehouse network separated from the office network]] | |||||
| New risks, and closed risks | [[e.g. none]] | |||||
| Decisions needed from executive management | [[e.g. R-01: funding for TA-01 goes to the board]] | |||||
Heat Map
Heat map
Where the risks sit on the 4 × 4 scale. Each cell shows its band in words and the number of risks in it. The colour only repeats the band.
| Now — residual (after existing controls) | Before controls — inherent | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Impact ↓ Likelihood → | 1 Unlikely | 2 Possible | 3 Likely | 4 Almost certain | Impact ↓ Likelihood → | 1 Unlikely | 2 Possible | 3 Likely | 4 Almost certain | |
| 4 Severe | Medium (4) — 2 | High (8) — 1 | Critical (12) — 0 | Critical (16) — 0 | 4 Severe | Medium (4) — 0 | High (8) — 2 | Critical (12) — 1 | Critical (16) — 0 | |
| 3 Major | Low (3) — 3 | Medium (6) — 1 | High (9) — 1 | Critical (12) — 0 | 3 Major | Low (3) — 0 | Medium (6) — 3 | High (9) — 2 | Critical (12) — 1 | |
| 2 Moderate | Low (2) — 1 | Medium (4) — 2 | Medium (6) — 1 | High (8) — 0 | 2 Moderate | Low (2) — 0 | Medium (4) — 2 | Medium (6) — 0 | High (8) — 1 | |
| 1 Minor | Low (1) — 0 | Low (2) — 0 | Low (3) — 0 | Medium (4) — 0 | 1 Minor | Low (1) — 0 | Low (2) — 0 | Low (3) — 0 | Medium (4) — 0 |
Each cell: band (score) — number of risks. Bands: Low 1–3; Medium 4–6; High 8–9; Critical 12–16. The score is impact × likelihood (RM-03).
Where a risk sits against appetite depends on its category as well as its band: read the Position against appetite column, not the colour.
Lists
| Level | Band | BandMinScore | AcceptApprover | AcceptReviewMonths | AppetiteLevel | LevelAppetite | LevelTolerance | Treatment | Trigger | Position |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Low | 1 | Risk owner | 12 | Averse | Low | Medium | Reduce | A major incident, or a near miss that shows a risk was underrated | Within appetite |
| 2 | Medium | 4 | Risk owner and Head of Information Security | 12 | Cautious | Medium | High | Avoid | A major change to systems, processes, suppliers or the organisation | Outside appetite, within tolerance |
| 3 | High | 8 | Accountable executive and Head of Information Security | 6 | Open | High | High | Transfer | A new or changed threat relevant to our services (threat intelligence) | Outside tolerance |
| 4 | Critical | 12 | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | 3 | Accept | An audit, test or assessment finding |
A change in law, regulation or a key contract
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Risk | The chance that a threat uses a weakness to harm a service or asset we depend on, with a consequence we can describe (RM-01). |
| Risk ID | Your unique reference for the risk, such as R-04. It stays the same while the risk is on the register. |
| Category | The kind of harm, which sets the appetite that applies. Your categories and their appetite levels are on the Appetite sheet. |
| Risk owner | Every risk has one named owner: the executive accountable for the service or asset it would hurt, not the security team. [[the accountable executive for the service or asset]] |
| Impact | 1 Minor: affects one system of Standard criticality or non-sensitive data; no customer or regulatory effect. 2 Moderate: affects a High criticality system or internal confidential data; limited, recoverable disruption. 3 Major: affects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong. 4 Severe: could stop a core business service, expose sensitive data at scale, or breach a legal obligation. Judged on the worst consequence; the Risk Assessment Methodology & Scoring Model gives the money and service thresholds. |
| Likelihood | 1 Unlikely: less than [[20]]% in the next 12 months. Not seen at organisations like ours in recent years, or only with rare skill or access. 2 Possible: [[20]]% to [[50]]% in the next 12 months. Happens regularly to organisations like ours; our controls make it harder but not rare. 3 Likely: [[50]]% to [[90]]% in the next 12 months. Happening now to organisations like ours, or has happened to us, and the gap is still open. 4 Almost certain: more than [[90]]% in the next 12 months, or already happening. Being attempted against us now, with little in the way. |
| Inherent score | Impact × likelihood as if the existing controls were not there, 1 to 16. |
| Residual score | Impact × likelihood with the existing controls working as they do today, 1 to 16. The residual band decides who must know and who may accept (RM-04). |
| Band | Low: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16. |
| Who must know | By residual band (RM-04): Low: risk owner; recorded in the register. Medium: risk owner and Head of Information Security. High: accountable executive and Head of Information Security; named to executive management in the quarterly report. Critical: executive management at once; the board chair out of cycle, within [[5]] working days (Critical is always outside tolerance). |
| Appetite level | Averse: we avoid this risk and act on anything above Low. Cautious: we accept some risk for a clear business benefit, with controls. Open: we accept higher risk to pursue opportunity; Critical is never within tolerance. |
| Position against appetite | Within appetite: the residual band is at or below the category's appetite. Outside appetite, within tolerance: above appetite but at or below tolerance, with a plan to bring it back. Outside tolerance: above the tolerance limit, where the board must act (RM-05). |
| Movement | Better, Same or Worse: this quarter's residual score against last quarter's. New: no score last quarter. |
| Treatment | Reduce: change the likelihood or the impact with controls. Avoid: stop the activity that creates the risk. Transfer: share the impact with a third party, for example by insurance or contract; the risk owner still owns the risk. Accept: keep the residual risk knowingly, recorded and approved at the right level (Risk Acceptance Form). |
| Linked actions | The IDs of the treatment actions in the Risk Treatment Plan, such as TA-01 (RM-07). |
| Who may accept | Low: risk owner; Medium: risk owner and Head of Information Security; High: accountable executive and Head of Information Security; Critical: the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management. Outside appetite, the band's approvers sign and executive management signs as well. Outside tolerance, the band's approvers can only recommend: only the board or its equivalent may accept (RM-08). |
| Acceptance ref, review date | The reference on the Risk Acceptance Form & Approval Record and the date the acceptance must be reviewed by: Low 12 months, Medium 12 months, High 6 months, Critical 3 months after approval. |
| Reviewed this quarter | Yes when the owner's last review is within the 3 months up to the as-at date (RM-09, RMM-04). |
| Trigger | An event that forces reassessment before the scheduled one (RM-10): a major incident, or a near miss that shows a risk was underrated; a major change to systems, processes, suppliers or the organisation; a new or changed threat relevant to our services (threat intelligence); an audit, test or assessment finding; a change in law, regulation or a key contract. |
| Trigger flag | Reassess by a date: reassess by then, 10 working days (Monday to Friday) after the trigger. Reassessment overdue: that date has passed. Reassessed: done on or after the trigger date. |
| Record check | A calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding. |
| As-at date | The date the review flag, trigger flag and acceptance check are measured against. Set on the Summary sheet. |
| EXAMPLE row | A worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval. |
| RM-nn, RMM-nn | Rule and measure numbers in the Risk Assessment Methodology & Scoring Model. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 6.1.2 — Information security risk assessment | The register as a whole: risks identified with owners, analysed and evaluated against criteria on the same scale every time |
| ISO/IEC 27001:2022 | Clause 8.2 — Information security risk assessment | Last owner review, trigger and reassessment columns: assessments repeated each quarter and on change, and kept as records |
| NIST CSF 2.0 | ID.RA-05 — “Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization” | Inherent and residual impact, likelihood, score and band; position against appetite used to prioritise treatment |
| NIST CSF 2.0 | GV.RM-06 — “A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated” | One scoring method for every risk: the scales, bands and position rule on the Lists and Appetite sheets |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 3(b) — a procedure and methodology for ICT risk assessment, with indicators to measure impact and likelihood | Impact and likelihood scales, scores and bands: the indicators used to assess ICT risk |
| DORA — Regulation (EU) 2022/2554 | Article 8(2) — identify all sources of ICT risk on a continuous basis and review the risk scenarios at least yearly | Trigger columns and the quarterly and yearly reassessment: risk sources identified continuously and scenarios reviewed at least yearly |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)