Dr. Vianney C.Cybersecurity Advisory
NIST SP 800-30 Rev.1 NIST CSF 2.0 ISO 27001:2022 CIS Controls v8.1

Cyber Risk Assessment

A structured, standards-aligned method for identifying assets, threats and vulnerabilities, then rating each risk by likelihood and impact to prioritize treatment. Complete the register below — risk levels are calculated automatically using the NIST SP 800-30 risk model.

Use Export to save your work.

1Assessment scope & methodology

Define the boundary of this assessment, then work through the five-step NIST SP 800-30 process. Record scope details here so the report stands alone.

Organization / System

Click to enter the assessed entity or system name…

Assessment date

Click to enter date…

Assessor / Lead

Click to enter name…

Risk appetite statement

e.g. "High and Very High risks require executive sign-off and a remediation plan within 30 days."

1
Prepare — Set purpose, scope, assumptions, information sources and the risk model.
2
Identify threat sources & events — Adversarial, accidental, structural, environmental.
3
Identify vulnerabilities — Weaknesses and predisposing conditions.
4
Determine likelihood & impact — Rate each on the five-level scale.
5
Determine & communicate risk — Combine into a risk level; assign treatment.

2Risk summary

Live totals update as you edit the register.

3Risk register

Add one row per identified risk. Select a Likelihood and Impact rating — the Risk column is computed automatically from the NIST SP 800-30 Table I-2 matrix. Use the Treatment column to record the response (Mitigate, Transfer, Avoid, Accept) and owner.

# Asset / Process Threat (source & event) Vulnerability Existing controls Likelihood Impact Risk Treatment Action & owner

4Risk heat map

The 5×5 matrix reflects the NIST SP 800-30 risk model (Likelihood × Impact → Risk level). Numbers in each cell show how many register entries currently fall there.

Likelihood ↑   /   Impact →
Risk level
Very High — 96–100 · urgent, executive action
High — 80–95 · severe/catastrophic effect
Moderate — 21–79 · serious adverse effect
Low — 5–20 · limited adverse effect
Very Low — 0–4 · negligible effect
Scales are exemplary per NIST SP 800-30. Calibrate thresholds and document rationale; a matrix aids judgment, it does not replace it.

5Rating scales

Reference definitions for consistent scoring across assessors (NIST SP 800-30 Rev.1, Appendices G & H).

LikelihoodMeaning
Very HighAlmost certain to occur / adversary almost certain to initiate.
HighHighly likely to occur or be initiated.
ModerateSomewhat likely to occur or be initiated.
LowUnlikely to occur or be initiated.
Very LowHighly unlikely to occur or be initiated.
ImpactMeaning
Very HighMultiple severe or catastrophic adverse effects.
HighSevere/catastrophic — major loss, inability to perform primary functions.
ModerateSerious — significant degradation, significant loss or harm.
LowLimited — minor degradation, minor loss or harm.
Very LowNegligible adverse effect.

6Control framework mapping

Each risk treatment should map to specific controls. Reference crosswalk of NIST CSF 2.0 Functions to the CIS Controls v8.1 and ISO 27001:2022 control families most commonly used to treat cyber risk.

NIST CSF 2.0 FunctionRepresentative categoriesCIS v8.1 / ISO 27001:2022
Govern (GV)Organizational context, risk strategy, roles, policy, oversight, supply-chain risk (GV.OC/RM/RR/PO/OV/SC)CIS 15, 17 · ISO A.5.1–A.5.8, A.5.19–A.5.23
Identify (ID)Asset management, risk assessment, improvement (ID.AM/RA/IM)CIS 1, 2, 3, 7 · ISO A.5.9–A.5.12, A.8.8
Protect (PR)Access control, training, data security, platform security, resilience (PR.AA/AT/DS/PS/IR)CIS 4, 5, 6, 10, 11, 12, 14 · ISO A.8.1–A.8.24
Detect (DE)Continuous monitoring, adverse event analysis (DE.CM/AE)CIS 8, 13 · ISO A.8.15–A.8.16
Respond (RS)Incident management, analysis, reporting, mitigation (RS.MA/AN/CO/MI)CIS 17 · ISO A.5.24–A.5.28
Recover (RC)Recovery plan execution, recovery communication (RC.RP/CO)CIS 11 · ISO A.5.29–A.5.30, A.8.13–A.8.14