All data is fictional

ISO 27001 Risk Register

Acme Corp — ISO 27001:2022

14

Total Risks

5

High / Critical

9.2

Avg Inherent Score

3

Mitigated
All Risks (14)
IDRisk TitleCategoryLikelihoodImpactScoreTreatmentStatusOwner
R-001Insufficient access control on admin APIsTechnical4520 CriticalTreatIn ProgressT. Richards
R-002Data breach via third-party data processorVendor3515 HighTransferOpenJ. Cooper
R-003Ransomware attack on workstationsTechnical3412 HighTreatIn ProgressS. Lin
R-004Employee sharing credentialsPeople4312 HighTreatOpenHR Dept
R-005Uncontrolled software deployment to productionProcess3412 HighTreatIn ProgressDev Lead
R-006Physical access to server room by visitorsPhysical2510 MediumTreatOpenFacilities
R-007Loss of key personnel (single point of failure)People339 MediumAcceptAcceptedManagement
R-008Outdated backup restoration procedureProcess248 MediumTreatIn ProgressIT Ops
R-009Failure to notify data subjects of breach in timeLegal248 MediumTreatOpenDPO
R-010Denial of Service attack on customer portalTechnical326 MediumTransferMitigatedCTO
R-011SQL injection in legacy web applicationTechnical236 MediumTreatIn ProgressDev Lead
R-012Supplier going out of businessVendor224 LowAcceptAcceptedProcurement
R-013Accidental deletion of production dataTechnical224 LowTreatMitigatedIT Ops
R-014Inadequate security awareness for new startersPeople313 LowTreatMitigatedHR Dept