Risk assesment

profileanilkumr23
risk_assessment.xlsx

Sheet1

Asset ID Common potential points of failure and known vulnerabilities Threat Type Threat sources Consequence Current Risk Likelihood Risk Rating Treatment Option & reference
People Personnel with low technical skills Availability T1,T2 Moderate Almost certain High Reduce A3
Careless about their personal informations such as user ids, password etc. People write it on stick notes paste on their desks T1,T2
short term contract employees T1,T2
People who resigned from the company can reveal the confidential information Confidentiality T1,T2 Moderate Likely High Reduce A1
Employees getting help from people outside organization to get their job done can lead to risk of revealing confidential information T1,T2
Unaware of consequences if something goes wrong while handling critical things T1,T2
All the employee activities such as system access, contacts etc should be monitored constantly Integrity T1,T2 Moderate Likely High Reduce A2
Unethical way of using organizations software or try to break it using virus or malicious code T1,T2
Management Various policies related to security issues have to be taken into consideration Integrity T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B2
No efficiency in work done by the employees T1, T2, T3, T4, T5
No proper agreements at various levels such as service level agreements T1, T2, T3, T4, T5
Poor allocation security roles and responsibilities, No proper authorization based on designation Confidentiality T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B1
Lack of appropiate response to the security issues T1, T2, T3, T4, T5
On frequent basis proper reviwening all operation procedures, implementations and planning Availability T1, T2, T3, T4, T5 Catastrophic Likely Extreme Reduce B3
weak and lame personnel in security committee T1, T2, T3, T4, T5
Building/Site management Lack of proper maintainence handeling Integrity T1, T2 Minor Possible Medium Reduce C2
Natural disasters T1, T2
losses and harm caused to personnel and service due to Environmental hazards Availability T1, T2 Moderate Unlikely Medium Reduce C3
No proper planning and designing T1, T2
No proper security for property and infrastructure T1, T2
Environment in office not secured or less secured Confidentiality T1, T2 Minor Possible Medium Reduce C1
Information Management Constantly monitoring and auditning the softwares Integrity T1, T2 Moderate Almost Certain High Reduce D2
Strong Password policy should be entact and enforced T1, T2
Ex-employees access id and password sould be regularly monitered to avoid un-authorized and illegally actvities T1, T2
Access control should be limted to concerned people to protect un authorized access T1, T2
Any software update should be done from licensed copies only Availability T1, T2 Moderate Almost Certain High Reduce D3
Installing inappropriate hardware/software or without proper knowledge T1, T2
Recovery plan or devices should be continously monitered T1, T2
unorganized and inadequacy in data management may leads to data breach Confidentiality T1, T2 Moderate Almost Certain High Reduce D1
Policies and procedures should be up to data and document T1, T2
T1, T2
Communication and Network Mis interpretation of information may results in breach of the data Confidentiality T1, T2 Minor Likely Medium Reduce E1
loop holes in policies, rules of network equipment. T1, T2
weak segment network leads to network valunerability T1, T2
Unprotected wireless channels grant unapproved access, network breach. T1, T2
Unethical hacking, cyber attacks, interruptions in data transmissions Integrity T1, T2 Moderate Almost Certain High Reduce E2
No proper time to time network activity analysis T1, T2
Eradicating irrelevant information Availability T1, T2 Moderate Almost Certain High Reduce E3
Obstruction from different devices T1, T2
SCADA Application Software Lack of new technology Integrity T1, T2 Major Likely High Reduce F2
Use of licensed software T1, T2
Challenges in maintaining the modern software T1, T2
Network crash Availability T1, T2 Major Likely High Reduce F3
User fails to cope up with the required often changes T1, T2
Lack of knowledge of the new introduced software T1, T2
Difficulty in software maintenance T1, T2
Problem faced through stern security Confidentiality T1, T2 Moderate Likely High Reduce F1
SCADA Hardware including operating System Application Inconsistency Integrity T1, T2 Moderate Likely High Reduce G2
Management failure Confidentiality T1, T2, T3, T4 Moderate Almost Certain High Reduce G1
possibility of system accessible by many T1, T2
Improper access codes T1, T2
Failure of equipment Availability T1, T2 Moderate Almost Certain High Reduce G3
Lack of extra quipment T1, T2
Power failures T1, T2
No proper monitoring and planning T1, T2
SCADA Field Devices Failure in security hardening Confidentiality T1, T2 Moderate Likely High Reduce H1
Having same default security configuration for every system T1, T2
Using older username and password T1, T2
physicial damage Availability T1, T2 Moderate Almost Certain High Reduce H3
access to the service T1, T2
Hardware and Software application Integrity T1, T2 Minor Likely Medium Reduce H2
use of other devices for operating T1, T2
Supporting Utilities power deficiency Integrity T1, T2 Moderate Likely High Reduce I2
backup power defieciency Availability T1, T2 Major Likely High Reduce I3
Capacity planning T1, T2
Damage to utilities which are used in support T1, T2
Breach of confidentiality Confidentiality T1, T2 Minor Possible Medium Reduce I1