Risk ownership and scoring
Learn your responsibilities as a risk owner
Written By Micah
I have been assigned ownership of a risk item, what now?
As a risk owner it is your responsibility to assign likelihood and impact scores to the risk, select a treatment plan, and activate controls to help mitigate the risk.
Once you've been assigned ownership of a risk, you'll need to complete the following steps:
A video demonstration of how to utilize Strike Graph's risk assessment tool can be found here.
Determine if the risk is applicable to your organization
The risks identified within Strike Graph are applicable to most businesses, but it is possible that some risks will not apply to your organization due to the nature of your business. For example, risks relating to Availability will not be applicable to a consulting firm that does not host any customer data. Risks can be designated as "Inactive" by clicking the Edit button near the risk title.

Assign likelihood and impact scores
If a risk is applicable to your organization, the next step is to assign likelihood and impact scores. Evaluate the risk based on the assumption that the suggested controls listed below the risk are already in place. This is called residual risk.
Scoring a risk involves assigning impact and likelihood values to create a combined risk score and then assigning a treatment.
Impact: If the risk were to occur how would it impact your organization?
Likelihood: What is the likelihood that a risk would occur?
Combined score: This is the weighted average between the impact and likelihood value. You should use this value to assess the treatment and mitigation strategy.
For example, in the screenshots below, the risk Acceptable Use of Company Assets has a suggested control Acceptable Use Policy. These "suggested controls" essentially outline the controls that will most likely be required for SOC 2 compliance, so you should evaluate the residual risk, assuming that the suggested control has been implemented (i.e. the control is "Active" AND "In place").

Risk scores can be listed as low, medium, or high. The below tables offer some guidance on how to assign risk scores, more guidance can be found within our Risk Management Policy template.
Impact:
Likelihood:
Select a treatment plan
After you've scored the risk, the next step is to select a treatment plan. Risk treatment refers to how your organization plans to address the risk. Your organization will use controls to reduce the impact and likelihood of a risk. Controls are mapped to compliance standard criteria.
The possible options for treating the risk are:
Selection or development of security controls: This will be by far the most common risk treatment. It is essentially saying that in order to reduce or mitigate the risk identified your organization will implement, or has already implemented a control.
Transfer the risk: This treatment is appropriate if you are outsourcing the process that the risk relates to. For example, if you are cloud-hosted, your hosting provider is responsible for managing the physical and environmental risks to your business on your behalf. In this scenario, it is appropriate to transfer the risks related to Physical Access Controls and Environment.
Discontinue: This treatment option will almost never be used, it essentially says that you will halt business activities that generate the identified risk.
Accept the risk: This treatment is only available for risks you've scored as low for both likelihood and impact. Accepting the risk is essentially saying that you believe the risk is low enough that implementing additional controls is not necessary.

Activate additional controls to mitigate the risk
Once you have scored a risk and assigned a treatment plan, the last step is to activate additional controls, depending on the risk level. Strike Graph comes pre-loaded with hundreds of common controls that can be used to mitigate risks. You can use the "Link Controls" button to link new controls to cover the risk or review the suggested controls and activate any that are relevant to your business profile. As mentioned above, our suggested controls will already be activated for each risk identified.

Going back to our example using the Acceptable Use of Company Assets risk above, if you scored that risk as "High" even with an Acceptable Use Policy in place, then you may want to implement additional controls, like a Malware Protection Policy, or Clear Desk Policy to help mitigate the risk.

Once you have completed the review and activated controls to mitigate the risk, press the "Mitigation Complete" button to change the risk progress to mitigated.
