Risks ranked by business impact, not CVSS
An ISO 27005 risk assessment that produces a treatment plan your executives will actually fund.
The challenge
Technical risk registers list vulnerabilities. Executives fund business risks. Translating one into the other is the whole job.
Scope — included and not included
Included
- Asset and process inventory
- Threat and vulnerability identification
- Likelihood and impact assessment
- Risk register
- Treatment plan with owners
- Residual risk statement
Not included
- Implementing the treatments
- Technical testing, that is a pentest
- Ongoing risk management unless retained
How it works
01
Scope and assets
What matters to the business, and what it runs on.
02
Identify and assess
Threats, vulnerabilities, likelihood and impact — in workshops with your people.
03
Rank and plan
The register, ranked, with a funded, owned treatment plan.
04
Present to leadership
The executive presentation and the residual risk statement for sign-off.
What you receive
- →Risk register in your format
- →Treatment plan with owners and dates
- →Residual risk statement for sign-off
- →Executive presentation
- →Methodology documentation for auditors
What we need from you
- ·Access to process owners
- ·Asset inventory or our help building one
- ·An executive sponsor to accept residual risk
- ·Workshop time
Timeline and engagement
2 to 4 weeks. Fixed scope.
Standards, methods and tooling
ISO 27005ISO 31000Portal hosted in Canada
Frequently asked questions