Risk Assessment

Help
These tools are designed for desktop use and work best on a larger screen.

Assessment Scope

Purpose: Define what you are assessing. Name the system or process, organization, assessor, and date, and describe the boundary, what is in or out of scope, and key dependencies. A clear scope keeps the assessment defensible and repeatable (SP 800-30 "Prepare").

Asset & Information Characteristics

Purpose: Characterize the asset and its data. Set the information type and FIPS 199 system categorization, then rate confidentiality, integrity, and availability impact. This drives the Impact side of risk: the worst-case harm if the system is compromised.

Industry & Regulatory Context

Threat Sources NIST SP 800-30 Table D-2

Purpose: Identify who or what could cause harm. Select the SP 800-30 Table D-2 threat sources that realistically apply and note specific actors, motivations, or intelligence. More applicable and capable sources raise the likelihood of threat-event initiation.

Known Vulnerabilities & Weaknesses

Purpose: List the weaknesses a threat could exploit. Type your own, pick a suggestion, browse the CWE database, or import deficiencies from another assessment, then rate each weakness's severity and exposure. These drive susceptibility: the chance an event succeeds.

Overall Ratings

Existing & Compensating Controls

Purpose: Record the controls already in place, with their implementation level and effectiveness, and map each to the weaknesses it covers. Controls reduce susceptibility (not whether a threat is attempted), lowering residual risk.

Overall Ratings

Assumptions & Constraints

Purpose: Document the assumptions and constraints behind this assessment: scope limits, data sources, and what testing was or was not performed. These frame how much confidence to place in the result. SP 800-30 Rev 1 (Section 3.1, Task 1-2) calls for stating the assumptions that shape the risk determination, including:
  • Threat assumptions: which threat sources and events are in or out of scope (e.g., nation-state actors assumed out of scope, insider threat assumed credible).
  • Vulnerability assumptions: what is taken as known vs. assumed (e.g., patch levels from a scan vs. self-reported).
  • Environmental / operational assumptions: the operating environment, dependencies, and conditions assumed to hold (e.g., the facility's physical controls, a vendor's stated uptime).
  • Likelihood & impact assumptions: the basis for the ratings (e.g., no historical incident data, so likelihood is judgment-based).

Assessor Notes

🔒

Fill in the assessment inputs to produce a NIST-aligned risk statement and score.

Save as JSON

.json

Import vulnerabilities and controls

Pull another assessment into this Risk Assessment in one step: deficiencies and gaps become vulnerabilities, and satisfied or implemented controls become existing controls. Rate and refine both from here.

Reset Assessment?

All saved progress will be permanently cleared. Save a JSON backup first, or reset without saving.