Turn threat and vulnerability findings into likelihood-times-impact ratings and control-adjusted residual risk, with the traceable rationale assessors expect. All in your browser.
Risk judgments made without a documented framework are difficult to justify, reproduce, or compare across time. SP 800-30 provides a structured vocabulary and process (threat sources, threat events, vulnerabilities, likelihood, impact) that transforms informal security intuition into auditable analysis.
Every risk entry in this tool maps to the SP 800-30 structure. When an auditor or AO asks how you arrived at a risk level, you have both the methodology citation and the specific assessment data to back it up.
Work through a tabbed SP 800-30 workflow. Every entry maps to SP 800-30 risk factor categories so your assessment is reproducible and methodology-traceable.
Start with system identification: name, boundary description, operational environment, and primary mission. Identify information types and categorization levels to anchor the risk assessment. Document the assessment purpose (initial assessment, periodic review, change-triggered) and the organizational tier (system, mission, or organizational level).
Select from SP 800-30 Appendix D/E threat source taxonomy: adversarial (nation-state, criminal, insider, competitor), accidental, structural (component failure), and environmental (natural disaster, infrastructure failure). Characterize adversarial sources by capability, intent, and targeting to link them to realistic threat events in the next step.
Document threat events: the specific attack scenarios or adverse events a threat source could initiate. For each threat event, identify the system vulnerabilities it could exploit: configuration weaknesses, missing controls, procedural gaps, architectural exposures. The tool presents SP 800-30 Appendix E threat event examples organized by threat source type.
Rate Likelihood of Initiation (adversarial) or Likelihood of Occurrence (non-adversarial) on a qualitative scale aligned to SP 800-30 Table G-2/G-3, then combined with susceptibility via Table G-5. Rate adverse impact across Confidentiality, Integrity, and Availability per Table H-2. The tool combines overall likelihood and impact into a semi-quantitative score and reads the overall risk level from the SP 800-30 Appendix I assessment scale (Table I-3).
Document the controls in place or planned for each risk, and rate each one's implementation level and effectiveness. The tool adjusts likelihood to produce a control-adjusted residual risk, and the Summary view presents your risks prioritized by severity to guide remediation sequencing.
A risk assessment is only useful if it can be shared, revisited, and updated. Pro adds the I/O layer so you can back up your work and move it between browsers or devices.
Save your complete risk assessment as a JSON file and reload it in a future session. Share drafts with colleagues or maintain a version archive as the system evolves over time.
Generate a CSV with all risk entries, likelihood and impact scores, and risk levels. It opens in any spreadsheet app such as Excel or Google Sheets, ready for distribution to leadership, AOs, or system owners who work outside the browser tool.
Produce a print-ready SP 800-30 aligned report with the risk rating, assessment details, and response plans formatted for inclusion in an ATO package or plan of action.
Compare snapshots across time to see how your risk posture evolves as controls are implemented. Track residual risk movement, remediation velocity, and closure rates over periodic assessments.
Start identifying threats and scoring risk levels immediately, with no setup and no account required. Pro adds the export layer when you're ready to share your findings.