| RISK - THREAT MATRIX |
| Threat
Risk | DDoS Attack | Criminal Hacking | Malware - Worm Intrusion | Economic Downturn | Ransomware | Malicious Code Injection - Trojan Attack | Phishing Attack | Insider Threat | Security Control Recommendations |
| Compromise Confidentiality of Sensitive Information - Data Exfiltration | Likelihood: Low
Impact: High
Risk Level: 2 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: Low
Impact: High
Risk Level: 2 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: Moderate
Impact: High
Risk Level: 7 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - AC Security Controls, data loss prevention mechanisms
ISO/IEC 27001/27002 - Data Protection Standards
NIST SP 800-171/FISMA/FIPS - Encryption Standards: end-to-end encryption
|
| Unauthorized Access | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: Low
Impact: High
Risk Level: 2 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: Moderate
Impact: High
Risk Level: 7 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - AC Security Controls: role-based controls, network segmentation, principle of least privileged, firewalls
ISO/IEC 27001/27002 - Information Systems Security Standards: IDS/ SIEM |
| Compromise Integrity of Identification and Authentication Mechanisms | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: Low
Impact: Moderate
Risk Level: 1 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Moderate
Impact: Low
Risk Level: 5 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - IA, AU, and CM Security Controls: multifactor authentication, event logging and auditing
ISO/IEC 27001/27002 - Information Systems Security Standards |
| Compromise Availability of Defense Sector Services, Networks, and/or Resources | Likelihood: High
Impact: Very High
Risk Level: 9 | Likelihood: Moderate
Impact: Very High
Risk Level: 8 | Likelihood: Moderate
Impact: Very High
Risk Level: 8 | Likelihood: Very Low
Impact: Very High
Risk Level: 2 | Likelihood: High
Impact: Very High
Risk Level: 9 | Likelihood: Moderate
Impact: Very High
Risk Level: 8 | Likelihood: Low
Impact: Very High
Risk Level: 3 | Likelihood: Low
Impact: Very High
Risk Level: 3 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - IR and CP Security Controls: incident response with digital forensics team, disaster recovery and contingency strategies
ISO/IEC 27001/27002 - Information Systems Security Standards |
| Breach or Compromise Integrity of Defense Sector | Likelihood: Moderate
Impact: Very High
Risk Level: 8 | Likelihood: Low
Impact: Very High
Risk Level: 7 | Likelihood: Low
Impact: Very High
Risk Level: 7 | Likelihood: Very Low
Impact: Very High
Risk Level: 2 | Likelihood: Moderate
Impact: Very High
Risk Level: 8 | Likelihood: Low
Impact: Very High
Risk Level: 7 | Likelihood: Very Low
Impact: Very High
Risk Level: 2 | Likelihood: Very Low
Impact: Very High
Risk Level: 2 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - AC, SC, SI, and CM Security Controls: Secure patch and configuration management, network security & monitoring technologies
ISO/IEC 27001/27002 - Information Systems Security Standards: IDS / SIEM |
| Supply Chain Compromise | Likelihood: Low
Impact: High
Risk Level: 2 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Low
Impact: Moderate
Risk Level: 1 | Likelihood: Moderate
Impact: High
Risk Level: 7 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: Very Low
Impact: Moderate
Risk Level: 1 | NIST SP 800-37 - Risk Management Framework
NIST Cyber Supply Chain Risk Management best practices and controls
ISO/IEC 27036 - ICT Supply Chain best practices and security controls
ISO/IEC 27001/27002 - Information Systems Security Standards |
| Compromise Software Vulnerabilities / Software Assurance | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Low
Impact: Moderate
Risk Level: 1 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Low
Impact: Moderate
Risk Level: 2 | Likelihood: Very Low
Impact: Moderate
Risk Level: 1 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - CM Controls, Vulnerability management, Secure SDLC
ISO/IEC 27001/27002 - Information Systems Security Standards: anti-malware software, SIEM event logging and auditing, secure patch management |
| Social Engineering | Likelihood: Very Low
Impact: High
Risk Level: 1 | Likelihood: High
Impact: Moderate
Risk Level: 7 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: Very Low
Impact: Very Low
Risk Level: 0 | Likelihood: High
Impact: High
Risk Level: 8 | Likelihood: Moderate
Impact: Moderate
Risk Level: 6 | Likelihood: Very High
Impact: Moderate
Risk Level: 8 | Likelihood: Very Low
Impact: Very Low
Risk Level: 0 | NIST SP 800-37 - Risk Management Framework
NIST SP 800-53 - AC, AT, IA Security Controls
ISO/IEC 27001/27002 - Information Systems Security Standards: information security awareness, education and training |
| Note: This table was developed by the Hytema New Zealand cyber team, and provides a risk-threat matrix with security control recommendations for the defense sector. The values for likelihood and impact include: very low, low, moderate, high, and very high. The values for risk level range from 0-10 with the following designations: 0-1 low insignificant risk (requires periodic review); 2-3 low risk (requires periodic review); 4-6 moderate risk (requires regular monitoring and risk reduction activites); 7-8 high risk (requires frequent monitoring and risk reduction activites); and 9-10 critical risk (requires frequent monitoring, risk reduction activites, and contingency strategies). |