SP 800-30 Rev 1 · NIST Risk Management · FIPS 199

Defensible SP 800-30 risk ratings your AO will actually sign off on

Turn threat and vulnerability findings into likelihood-times-impact ratings and control-adjusted residual risk, with the traceable rationale assessors expect. All in your browser.

Open Risk Tool →
From Gut Feel to Documented Methodology

Risk scoring grounded in SP 800-30.

Risk judgments made without a documented framework are difficult to justify, reproduce, or compare across time. SP 800-30 provides a structured vocabulary and process (threat sources, threat events, vulnerabilities, likelihood, impact) that transforms informal security intuition into auditable analysis.

Every risk entry in this tool maps to the SP 800-30 structure. When an auditor or AO asks how you arrived at a risk level, you have both the methodology citation and the specific assessment data to back it up.

Risk Heat Map Likelihood × Impact LIKELIHOOD IMPACT VH H M L VL VL L M H VH R1 R2 R3 R4 R5 R6
How It Works

SP 800-30 structure, simplified.

Work through a tabbed SP 800-30 workflow. Every entry maps to SP 800-30 risk factor categories so your assessment is reproducible and methodology-traceable.

01Define Scope & System Context

Start with system identification: name, boundary description, operational environment, and primary mission. Identify information types and categorization levels to anchor the risk assessment. Document the assessment purpose (initial assessment, periodic review, change-triggered) and the organizational tier (system, mission, or organizational level).

02Identify Threat Sources

Select from SP 800-30 Appendix D/E threat source taxonomy: adversarial (nation-state, criminal, insider, competitor), accidental, structural (component failure), and environmental (natural disaster, infrastructure failure). Characterize adversarial sources by capability, intent, and targeting to link them to realistic threat events in the next step.

03Identify Threat Events & Vulnerabilities

Document threat events: the specific attack scenarios or adverse events a threat source could initiate. For each threat event, identify the system vulnerabilities it could exploit: configuration weaknesses, missing controls, procedural gaps, architectural exposures. The tool presents SP 800-30 Appendix E threat event examples organized by threat source type.

04Score Likelihood & Impact

Rate Likelihood of Initiation (adversarial) or Likelihood of Occurrence (non-adversarial) on a qualitative scale aligned to SP 800-30 Table G-2/G-3, then combined with susceptibility via Table G-5. Rate adverse impact across Confidentiality, Integrity, and Availability per Table H-2. The tool combines overall likelihood and impact into a semi-quantitative score and reads the overall risk level from the SP 800-30 Appendix I assessment scale (Table I-3).

05Controls & Residual Risk

Document the controls in place or planned for each risk, and rate each one's implementation level and effectiveness. The tool adjusts likelihood to produce a control-adjusted residual risk, and the Summary view presents your risks prioritized by severity to guide remediation sequencing.

Pro Features

Save your register. Present your findings.

A risk assessment is only useful if it can be shared, revisited, and updated. Pro adds the I/O layer so you can back up your work and move it between browsers or devices.

  • Export & Import JSON

    Save your complete risk assessment as a JSON file and reload it in a future session. Share drafts with colleagues or maintain a version archive as the system evolves over time.

  • Export Risk Assessment to CSV

    Generate a CSV with all risk entries, likelihood and impact scores, and risk levels. It opens in any spreadsheet app such as Excel or Google Sheets, ready for distribution to leadership, AOs, or system owners who work outside the browser tool.

  • Print Formatted Risk Assessment Report

    Produce a print-ready SP 800-30 aligned report with the risk rating, assessment details, and response plans formatted for inclusion in an ATO package or plan of action.

  • Risk Trend Tracking

    Compare snapshots across time to see how your risk posture evolves as controls are implemented. Track residual risk movement, remediation velocity, and closure rates over periodic assessments.

Risk Assessment HRIS Platform · SP 800-30 Rev 1 · 6 risks identified ID Threat Event LH IMP LEVEL R1 Unpatched OS — Exploitation Threat-initiated · missing patch mgmt H H VERY HIGH R2 Credential Compromise (Phishing) Adversarial · weak MFA enrollment VH M VERY HIGH R3 Data Exfiltration via API M VH HIGH R4 Insider Threat — Privilege Abuse L H HIGH R5 Supply Chain Compromise L M MODERATE R6 Physical Facility Breach VL M LOW Very High: 2 High: 2 Moderate: 1 Low: 1 4 of 6 risks have active remediation plans Remediation Progress 67% 💾 Export JSON 🖨️ Print Report

Build an SP 800-30 risk assessment that holds up to scrutiny.

Start identifying threats and scoring risk levels immediately, with no setup and no account required. Pro adds the export layer when you're ready to share your findings.