1Assessment scope & methodology
Define the boundary of this assessment, then work through the five-step NIST SP 800-30 process. Record scope details here so the report stands alone.
Organization / System
Click to enter the assessed entity or system name…
Assessment date
Click to enter date…
Assessor / Lead
Click to enter name…
Risk appetite statement
e.g. "High and Very High risks require executive sign-off and a remediation plan within 30 days."
2Risk summary
Live totals update as you edit the register.
3Risk register
Add one row per identified risk. Select a Likelihood and Impact rating — the Risk column is computed automatically from the NIST SP 800-30 Table I-2 matrix. Use the Treatment column to record the response (Mitigate, Transfer, Avoid, Accept) and owner.
| # | Asset / Process | Threat (source & event) | Vulnerability | Existing controls | Likelihood | Impact | Risk | Treatment | Action & owner |
|---|
4Risk heat map
The 5×5 matrix reflects the NIST SP 800-30 risk model (Likelihood × Impact → Risk level). Numbers in each cell show how many register entries currently fall there.
5Rating scales
Reference definitions for consistent scoring across assessors (NIST SP 800-30 Rev.1, Appendices G & H).
| Likelihood | Meaning |
|---|---|
| Very High | Almost certain to occur / adversary almost certain to initiate. |
| High | Highly likely to occur or be initiated. |
| Moderate | Somewhat likely to occur or be initiated. |
| Low | Unlikely to occur or be initiated. |
| Very Low | Highly unlikely to occur or be initiated. |
| Impact | Meaning |
|---|---|
| Very High | Multiple severe or catastrophic adverse effects. |
| High | Severe/catastrophic — major loss, inability to perform primary functions. |
| Moderate | Serious — significant degradation, significant loss or harm. |
| Low | Limited — minor degradation, minor loss or harm. |
| Very Low | Negligible adverse effect. |
6Control framework mapping
Each risk treatment should map to specific controls. Reference crosswalk of NIST CSF 2.0 Functions to the CIS Controls v8.1 and ISO 27001:2022 control families most commonly used to treat cyber risk.
| NIST CSF 2.0 Function | Representative categories | CIS v8.1 / ISO 27001:2022 |
|---|---|---|
| Govern (GV) | Organizational context, risk strategy, roles, policy, oversight, supply-chain risk (GV.OC/RM/RR/PO/OV/SC) | CIS 15, 17 · ISO A.5.1–A.5.8, A.5.19–A.5.23 |
| Identify (ID) | Asset management, risk assessment, improvement (ID.AM/RA/IM) | CIS 1, 2, 3, 7 · ISO A.5.9–A.5.12, A.8.8 |
| Protect (PR) | Access control, training, data security, platform security, resilience (PR.AA/AT/DS/PS/IR) | CIS 4, 5, 6, 10, 11, 12, 14 · ISO A.8.1–A.8.24 |
| Detect (DE) | Continuous monitoring, adverse event analysis (DE.CM/AE) | CIS 8, 13 · ISO A.8.15–A.8.16 |
| Respond (RS) | Incident management, analysis, reporting, mitigation (RS.MA/AN/CO/MI) | CIS 17 · ISO A.5.24–A.5.28 |
| Recover (RC) | Recovery plan execution, recovery communication (RC.RP/CO) | CIS 11 · ISO A.5.29–A.5.30, A.8.13–A.8.14 |