Sie sind auf Seite 1von 4

Sheet1

PERA Information Group, PLC


Infosec Risk Assesment form

No Asset ID Asset Name Threat

Intentional
accidental
1 NCI-IN-001-00 CRM Data Base Data lost/deleted V V

Stolen V

Corrupt V
Miss input V V

PERA Neville Clarke Infosec Management


Copyright by DY

Page 1
Sheet1

Vulnearbility Impact Description C I A Likelyhood

People competence
Confidentiality

Impact value

Past History
Availability
Integrity
Natural

Impact Rating
V malfunction UPS, customer data lost 3 5 3 11 M 1 3
lack of awareness,
earthquake
no password,
weak perimeter security

no updated antivirus
lack of competency

Page 2
Sheet1

Likelyhood
Current Protection

Likelihood value
Probability

Likelihood
Rating Risk Value Control Method
1 1 6L L

Page 3
Sheet2

1 0~1000
2 10
3

Page 4

Das könnte Ihnen auch gefallen