These tools are designed for desktop use and work best on a larger screen.
Assessment Scope
Purpose: Define what you are assessing. Name the system or process, organization, assessor, and date, and describe the boundary, what is in or out of scope, and key dependencies. A clear scope keeps the assessment defensible and repeatable (SP 800-30 "Prepare").
Asset & Information Characteristics
Purpose: Characterize the asset and its data. Set the information type and FIPS 199 system categorization, then rate confidentiality, integrity, and availability impact. This drives the Impact side of risk: the worst-case harm if the system is compromised.
Industry & Regulatory Context
Threat Sources NIST SP 800-30 Table D-2
Purpose: Identify who or what could cause harm. Select the SP 800-30 Table D-2 threat sources that realistically apply and note specific actors, motivations, or intelligence. More applicable and capable sources raise the likelihood of threat-event initiation.
Known Vulnerabilities & Weaknesses
Purpose: List the weaknesses a threat could exploit. Type your own, pick a suggestion, browse the CWE database, or import deficiencies from another assessment, then rate each weakness's severity and exposure. These drive susceptibility: the chance an event succeeds.
Overall Ratings
—
Vulnerability / WeaknessSeverityExposure
Existing & Compensating Controls
Purpose: Record the controls already in place, with their implementation level and effectiveness, and map each to the weaknesses it covers. Controls reduce susceptibility (not whether a threat is attempted), lowering residual risk.
Imported findings: Weaknesses pulled from another assessment appear as vulnerabilities, and satisfied controls appear in this list. Open a control and select the weaknesses it covers; each covered weakness gets a lower residual rating, so you can see what addressing it buys. Coverage does not change a control's implementation level (the two are independent).
Overall Ratings
—
—
ControlImplementation LevelEffectiveness
Assumptions & Constraints
Purpose: Document the assumptions and constraints behind this assessment: scope limits, data sources, and what testing was or was not performed. These frame how much confidence to place in the result. SP 800-30 Rev 1 (Section 3.1, Task 1-2) calls for stating the assumptions that shape the risk determination, including:
Threat assumptions: which threat sources and events are in or out of scope (e.g., nation-state actors assumed out of scope, insider threat assumed credible).
Vulnerability assumptions: what is taken as known vs. assumed (e.g., patch levels from a scan vs. self-reported).
Environmental / operational assumptions: the operating environment, dependencies, and conditions assumed to hold (e.g., the facility's physical controls, a vendor's stated uptime).
Likelihood & impact assumptions: the basis for the ratings (e.g., no historical incident data, so likelihood is judgment-based).
Assessor Notes
🔒
Fill in the assessment inputs to produce a NIST-aligned risk statement and score.
Risk Score Over Time
Track how this system's overall risk score trends as you remediate. Import JSON files you previously saved from this Risk Assessment tool; the live assessment is plotted as the most recent point.
Save as JSON
.json
Import vulnerabilities and controls
Pull another assessment into this Risk Assessment in one step: deficiencies and gaps become vulnerabilities, and satisfied or implemented controls become existing controls. Rate and refine both from here.
Reset Assessment?
All saved progress will be permanently cleared. Save a JSON backup first, or reset without saving.