1 of 6

Risk Assessment Guide

2 of 6

Instructions:

  • Form a group max of 5 members (ideally from the same department with a supervisor/manager)
  • Brainstorm and identify Threats and Vulnerabilities related to assets that are in scope of your department/role.
  • Rate the threat and vulnerability identified as well as its impact.
  • Identify a risk approach.
  • This will be submitted at the end of the session and align with ICT Policy.

Risk Assessment Summary

3 of 6

Group Activity: Assessment Guide

Risk Assessment Summary

4 of 6

Risk Analysis– 45 minutes

Risk Assessment Summary

Threat

Vulnerability

 Exploit known critical OS vuln

Unpatched servers 

 

 

 

 

 

 

 

 

5 of 6

Risk Rating

Risk Assessment Summary

Identified Threat

Threat Value

Vulnerability Value

Impact Value

Risk Rating

(T x V x I)

 Ex. Exploit known critical OS vuln

3

3

27 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

6 of 6

Risk Approach

Risk Assessment Summary

Identified Threat

Risk Approach

Potential Control

 Ex. Exploit known critical OS vuln

 Risk Mitigation

Implement change control, patch and test the server.