Risk assessment for a bank as per the outline given. Must follow the outline and rules
List of Current and Planned Controls
Step 4. Control Analysis
Threat Statement Step 2.
Threat Identification
List of Potential Vulnerabilities
Step 3. Vulnerability Identification
• Reports from prior risk assessments
• Any audit comments • Security requirements • Security test results
• Hardware • Software • System interfaces • Data and information • People • System mission
Step 1. System Characterization
Likelihood RatingStep 5. Likelihood Determination
• Threat source motivation • Threat capacity • Nature of vulnerability • Current controls
Step 9. Results Documentation
Risk Assessment Report
Step 6. Impact Analysis
• Loss of Integrity • Loss of Availability • Loss of Confidentiality
Impact Rating
• Mission impact analysis • Asset criticality assessment • Data criticality • Data sensitivity
Risks and Associated Risk
Levels Step 7. Risk Determination
• Likelihood of threat exploitation
• Magnitude of impact • Adequacy of planned or
current controls
Recommended Controls
Step 8. Control Recommendations
• System Boundary • System Functions • System and Data
Criticality • System and Data
Sensitivity
• Current controls • Planned controls
• History of system attack • Data from intelligence
agencies, NIPC, OIG, FedCIRC, mass media,
List of Current and Planned Controls
• Reports from prior risk
assessments • Any audit comments • Security requirements • Security test results
• Current controls • Planned controls
InpInpuutt RiRisksk AsseAssessmssmeenntt AcActtiivivittiieess
Step 1. System Characterization
OutOutpputut
Threat Statement Step 2.
Threat Identification
• Hardware • Software • System interfaces • Data and information • People • System mission
• System Boundary • System Functions • System and Data
Criticality • System and Data
Sensitivity
• History of system attack • Data from intelligence
agencies, NIPC, OIG, FedCIRC, mass media,
List of Potential Vulnerabilities
Step 3. Vulnerability Identification
• Reports from prior risk assessments
• Any audit comments • Security requirements • Security test results
-
List of Current and Planned Controls
Step 4. Control Analysis
Likelihood RatingStep 5. Likelihood Determination
• Threat-source motivation • Threat capacity • Nature of vulnerability • Current controls
• Current controls • Planned controls
• Mission impact analysis • Asset criticality assessment • Data criticality • Data sensitivity
• Likelihood of threat exploitation
• Magnitude of impact • Adequacy of planned or
current controls
Step 6. Impact Analysis
• Loss of Integrity • Loss of Availability • Loss of Confidentiality
Impact Rating
Step 7. Risk Determination Risks and
Associated Risk Levels
Step 9. Results Documentation
Risk Assessment Report
Recommended Controls
Step 8. Control Recommendations
Figure 3-1. Risk Assessment Methodology Flowchart
SP 800-30 Page 9