Risk Assessment & Treatment Methodology (Clause 6 & 8)
1. Overview
The organization uses a standard qualitative 5x5 Risk Matrix assessing Likelihood vs. Impact across Confidentiality, Integrity, and Availability (CIA).
$$\text{Risk Score} = \text{Likelihood (1–5)} \times \text{Impact (1–5)}$$
2. Scoring Criteria
Likelihood Scale
- Rare: Improbable, occurs once every 5+ years.
- Unlikely: Possible, but not anticipated (once every 2–3 years).
- Possible: Might occur at some point (annual frequency).
- Likely: Expected to occur multiple times per year.
- Almost Certain: Regular or continuous occurrence.
Impact Scale (Commercial, Operational, Legal)
- Insignificant: Negligible operational drag; <£1,000 loss.
- Minor: Localized IT disruption; minor customer inconvenience; <£10,000.
- Moderate: Partial service outage; minor regulatory notice; £10,000–£50,000.
- Major: Significant customer downtime; material data breach; £50,000–£250,000.
- Catastrophic: Critical business paralysis; irreversible brand loss; >£250,000.
3. Risk Threshold & Treatment Options
| Score | Rating | Required Action |
|---|---|---|
| 1 – 6 | Low | Accept risk; monitor during periodic review. |
| 8 – 12 | Medium | Mitigate; implement operational controls within 60 days. |
| 15 – 25 | High / Critical | Immediate mitigation; executive sign-off required for any temporary acceptance. |