When you have completed the Risk Threat Matrix, a designated team member should submit it for feedback.

Michelle_Michy
20200523165434hytemanz_p4_risk_threat_matrix__1_.xlsx

Sheet1

RISK - THREAT MATRIX
Threat Risk DDoS Attack Criminal Hacking Malware - Worm Intrusion Economic Downturn Ransomware Malicious Code Injection - Trojan Attack Phishing Attack Insider Threat Security Control Recommendations
Compromise Confidentiality of Sensitive Information - Data Exfiltration Likelihood: Low Impact: High Risk Level: 2 Likelihood: High Impact: High Risk Level: 8 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: Low Impact: High Risk Level: 2 Likelihood: High Impact: High Risk Level: 8 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: Moderate Impact: High Risk Level: 7 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - AC Security Controls, data loss prevention mechanisms ISO/IEC 27001/27002 - Data Protection Standards NIST SP 800-171/FISMA/FIPS - Encryption Standards: end-to-end encryption
Unauthorized Access Likelihood: High Impact: High Risk Level: 8 Likelihood: High Impact: High Risk Level: 8 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: Low Impact: High Risk Level: 2 Likelihood: High Impact: High Risk Level: 8 Likelihood: High Impact: High Risk Level: 8 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: Moderate Impact: High Risk Level: 7 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - AC Security Controls: role-based controls, network segmentation, principle of least privileged, firewalls ISO/IEC 27001/27002 - Information Systems Security Standards: IDS/ SIEM
Compromise Integrity of Identification and Authentication Mechanisms Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: Low Impact: Moderate Risk Level: 1 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Moderate Impact: Low Risk Level: 5 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - IA, AU, and CM Security Controls: multifactor authentication, event logging and auditing ISO/IEC 27001/27002 - Information Systems Security Standards
Compromise Availability of Defense Sector Services, Networks, and/or Resources Likelihood: High Impact: Very High Risk Level: 9 Likelihood: Moderate Impact: Very High Risk Level: 8 Likelihood: Moderate Impact: Very High Risk Level: 8 Likelihood: Very Low Impact: Very High Risk Level: 2 Likelihood: High Impact: Very High Risk Level: 9 Likelihood: Moderate Impact: Very High Risk Level: 8 Likelihood: Low Impact: Very High Risk Level: 3 Likelihood: Low Impact: Very High Risk Level: 3 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - IR and CP Security Controls: incident response with digital forensics team, disaster recovery and contingency strategies ISO/IEC 27001/27002 - Information Systems Security Standards
Breach or Compromise Integrity of Defense Sector Likelihood: Moderate Impact: Very High Risk Level: 8 Likelihood: Low Impact: Very High Risk Level: 7 Likelihood: Low Impact: Very High Risk Level: 7 Likelihood: Very Low Impact: Very High Risk Level: 2 Likelihood: Moderate Impact: Very High Risk Level: 8 Likelihood: Low Impact: Very High Risk Level: 7 Likelihood: Very Low Impact: Very High Risk Level: 2 Likelihood: Very Low Impact: Very High Risk Level: 2 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - AC, SC, SI, and CM Security Controls: Secure patch and configuration management, network security & monitoring technologies ISO/IEC 27001/27002 - Information Systems Security Standards: IDS / SIEM
Supply Chain Compromise Likelihood: Low Impact: High Risk Level: 2 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: High Impact: High Risk Level: 8 Likelihood: Low Impact: Moderate Risk Level: 1 Likelihood: Moderate Impact: High Risk Level: 7 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: Very Low Impact: Moderate Risk Level: 1 NIST SP 800-37 - Risk Management Framework NIST Cyber Supply Chain Risk Management best practices and controls ISO/IEC 27036 - ICT Supply Chain best practices and security controls ISO/IEC 27001/27002 - Information Systems Security Standards
Compromise Software Vulnerabilities / Software Assurance Likelihood: High Impact: High Risk Level: 8 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Low Impact: Moderate Risk Level: 1 Likelihood: High Impact: High Risk Level: 8 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Low Impact: Moderate Risk Level: 2 Likelihood: Very Low Impact: Moderate Risk Level: 1 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - CM Controls, Vulnerability management, Secure SDLC ISO/IEC 27001/27002 - Information Systems Security Standards: anti-malware software, SIEM event logging and auditing, secure patch management
Social Engineering Likelihood: Very Low Impact: High Risk Level: 1 Likelihood: High Impact: Moderate Risk Level: 7 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: Very Low Impact: Very Low Risk Level: 0 Likelihood: High Impact: High Risk Level: 8 Likelihood: Moderate Impact: Moderate Risk Level: 6 Likelihood: Very High Impact: Moderate Risk Level: 8 Likelihood: Very Low Impact: Very Low Risk Level: 0 NIST SP 800-37 - Risk Management Framework NIST SP 800-53 - AC, AT, IA Security Controls ISO/IEC 27001/27002 - Information Systems Security Standards: information security awareness, education and training
Note: This table was developed by the Hytema New Zealand cyber team, and provides a risk-threat matrix with security control recommendations for the defense sector. The values for likelihood and impact include: very low, low, moderate, high, and very high. The values for risk level range from 0-10 with the following designations: 0-1 low insignificant risk (requires periodic review); 2-3 low risk (requires periodic review); 4-6 moderate risk (requires regular monitoring and risk reduction activites); 7-8 high risk (requires frequent monitoring and risk reduction activites); and 9-10 critical risk (requires frequent monitoring, risk reduction activites, and contingency strategies).