Risk ownership and scoring

Learn your responsibilities as a risk owner

Written By Micah

I have been assigned ownership of a risk item, what now?

As a risk owner it is your responsibility to assign likelihood and impact scores to the risk, select a treatment plan, and activate controls to help mitigate the risk.

Once you've been assigned ownership of a risk, you'll need to complete the following steps:

A video demonstration of how to utilize Strike Graph's risk assessment tool can be found here.

Determine if the risk is applicable to your organization

The risks identified within Strike Graph are applicable to most businesses, but it is possible that some risks will not apply to your organization due to the nature of your business. For example, risks relating to Availability will not be applicable to a consulting firm that does not host any customer data. Risks can be designated as "Inactive" by clicking the Edit button near the risk title.

Assign likelihood and impact scores

If a risk is applicable to your organization, the next step is to assign likelihood and impact scores. Evaluate the risk based on the assumption that the suggested controls listed below the risk are already in place. This is called residual risk.

Scoring a risk involves assigning impact and likelihood values to create a combined risk score and then assigning a treatment.

  • Impact: If the risk were to occur how would it impact your organization?

  • Likelihood: What is the likelihood that a risk would occur?

  • Combined score: This is the weighted average between the impact and likelihood value. You should use this value to assess the treatment and mitigation strategy.

For example, in the screenshots below, the risk Acceptable Use of Company Assets has a suggested control Acceptable Use Policy. These "suggested controls" essentially outline the controls that will most likely be required for SOC 2 compliance, so you should evaluate the residual risk, assuming that the suggested control has been implemented (i.e. the control is "Active" AND "In place").

Risk scores can be listed as low, medium, or high. The below tables offer some guidance on how to assign risk scores, more guidance can be found within our Risk Management Policy template.

Impact:

Rating

Descriptor

Financial Loss

Reputation

Legal

High

Major

Greater than $100k

Loss of 1+ anchor client

Report to regulators with major corrective action, possible fines

Medium

Moderate

$50k - $100k

Regional reputational damage

Breach notification to clients or customers, corrective action

Low

Minor

Less than $50k

Solved with a phone call

Not reportable

Likelihood:

Rating

Descriptor

Frequency

Probability

(chance of occurrence over the life of the asset, project, contract)

High

Frequent/Almost Certain

Once every year or two

65%-100% chance

Medium

Possible

once every two to five years

35%-65% chance

Low

Unlikely

Once every five years

0%-35% chance

Select a treatment plan

After you've scored the risk, the next step is to select a treatment plan. Risk treatment refers to how your organization plans to address the risk. Your organization will use controls to reduce the impact and likelihood of a risk. Controls are mapped to compliance standard criteria.

The possible options for treating the risk are:

  1. Selection or development of security controls: This will be by far the most common risk treatment. It is essentially saying that in order to reduce or mitigate the risk identified your organization will implement, or has already implemented a control.

  2. Transfer the risk: This treatment is appropriate if you are outsourcing the process that the risk relates to. For example, if you are cloud-hosted, your hosting provider is responsible for managing the physical and environmental risks to your business on your behalf. In this scenario, it is appropriate to transfer the risks related to Physical Access Controls and Environment.

  3. Discontinue: This treatment option will almost never be used, it essentially says that you will halt business activities that generate the identified risk.

  4. Accept the risk: This treatment is only available for risks you've scored as low for both likelihood and impact. Accepting the risk is essentially saying that you believe the risk is low enough that implementing additional controls is not necessary.

Activate additional controls to mitigate the risk

Once you have scored a risk and assigned a treatment plan, the last step is to activate additional controls, depending on the risk level. Strike Graph comes pre-loaded with hundreds of common controls that can be used to mitigate risks. You can use the "Link Controls" button to link new controls to cover the risk or review the suggested controls and activate any that are relevant to your business profile. As mentioned above, our suggested controls will already be activated for each risk identified.

Going back to our example using the Acceptable Use of Company Assets risk above, if you scored that risk as "High" even with an Acceptable Use Policy in place, then you may want to implement additional controls, like a Malware Protection Policy, or Clear Desk Policy to help mitigate the risk.

Once you have completed the review and activated controls to mitigate the risk, press the "Mitigation Complete" button to change the risk progress to mitigated.

Screenshot showing suggested controls and mitigation button