Nine dimensions, one number
A risk analysis ends in a number. The matrix, the priority and the measure all follow from it. What it does not say is what kind of damage is meant. Why the maximum principle stays the default and a weighted average is a decision you have to justify.
A risk analysis ends in a number. It determines the position in the matrix, the order of measures and, ultimately, what money is spent on.
What it does not say is what kind of damage is meant.
"Impact: high" may mean an outage becomes expensive, that a supervisory authority imposes a fine, or that data subjects are harmed in their rights. Three different matters, three different countermeasures, one number. Anyone asking six months later why the risk was rated high will not find the reasoning.
Nine dimensions, two scopes
The assessment can therefore be split across individual dimensions. Nine are prepared, and they do not all apply everywhere.
In the risk analysis: financial, regulatory and legal, competitive disadvantage.
In the business impact analysis: operational impact, compliance, legal impact, data protection, contractual impact.
In both: reputation. It is the only one that asks the same question in both procedures.
That separation is not a filing convention, it follows the substance. The risk analysis rates how bad an event would be. The BIA rates what an outage does during emergency operation. Those are, as described elsewhere, two questions and not one.
Nine values become one number again
There are two methods for that, and the choice is a methodological decision, not a setting.
The default is the maximum principle: the highest rated dimension prevails. That is the rule IT-Grundschutz prescribes for inheriting protection needs, and it has a good reason. A fine does not shrink because the financial damage is small.
A weighted average is available as an alternative, rounded up. It reflects that in some organisations one dimension weighs more than another.
But it has a property you need to know before switching it on: it smooths. A risk with one very high regulatory dimension and five low ones lands in the unremarkable middle. That risk is precisely the one that gets an organisation into trouble.
Hence the maximum is the default and the average is the deliberate deviation.
An unrated dimension is not a zero
Only dimensions that were actually rated enter the calculation. An empty dimension is not counted as "no damage".
The difference is not academic. If an unrated dimension counted as zero, every column nobody has filled in yet would drag the average down, and a half-finished risk would look more harmless than an untouched one. The completeness of data entry would distort the assessment, in the dangerous direction.
Having entered nothing is not a statement about damage. It is the absence of a statement.
The whole thing ships switched off
All nine dimensions arrive inactive. After the update nothing changes for any organisation: the configuration screen is pre-filled rather than empty, but it switches nothing on. That is deliberate. An assessment methodology should not be introduced by an update, because switching it on changes the numbers your measure planning rests on.
Afterwards, too, the old number stays where it was. The risk matrix, the risk register, the ISO 27001 view, the OSCAL export and the API all hang off it, so the value derived from the dimensions is written back into exactly that column. It is simply no longer entered but derived.
The question to ask of your own records
Take three risks rated high in your organisation and ask: high in what respect?
If the answer is in the documentation, all is well. If it lives only in the head of the person who entered it, the rating is an opinion with a number in front of it. And when that person leaves, only the number remains.
More about the module on the Risk Register module page.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.