Risk Assessment Policy
Risk Assessment Policy
Section titled “Risk Assessment Policy”Authorized By: Chief Information Security Officer (CISO)
Purpose/Overview
Section titled “Purpose/Overview”This Policy provides a framework for identifying cybersecurity risks and vulnerabilities so that Safire can implement comprehensive solutions to address those risks and vulnerabilities. A Risk Assessment will ensure that Safire, Inc is aware of, and can adequately protect itself from, new risks and vulnerabilities that constantly arise with respect to cybersecurity, and to ensure Safire’s data and other related assets are protected to the greatest extent possible.
To that end, Safire will conduct a Risk Assessment of its Information Systems which will inform the design of its Cybersecurity Program. Safire will conduct Risk Assessments periodically and update its Risk Assessment as necessary to address changes to the company’s Information Systems, Non-Public Information (“NPI”), or business operations. Safire’s Risk Assessment will be conducted in accordance with this Policy.
This Policy covers all Safire activities across all areas of its business. It applies to all employees, including contractors, service providers and anyone with access to Safire’s data and related assets.
Policy
Section titled “Policy”Roles and Responsibilities
Section titled “Roles and Responsibilities”The Senior Executive Team will approve criteria established by the CISO for:
- Evaluating and categorizing cyber risks and threats facing Safire.
- Assessing the confidentiality, integrity, and availability of Safire’s Information Systems and its technology assets, including all data and NPI.
- Mitigating or accepting risk identified by the Risk Assessment.
- Evaluating the adequacy of existing controls in the context of identified risks.
- Updating the Risk Assessment at least annually to address new risks resulting from changes to Information Systems, business operations, or new products and services.
Risk Assessment
Section titled “Risk Assessment”The Risk Assessment will assist Safire in understanding, managing, controlling, and mitigating cyber risk by establishing a formal set of guidelines to:
- Identify and Prioritize Assets
- Identify Threats
- Identify Vulnerability
- Determine Likelihood and Impact
- Determine Inherent Risks
- Analyze Controls
- Determine Control Effectiveness
- Analyze Residual Risks
Document Results
Section titled “Document Results”Identifying and Prioritizing Assets
Section titled “Identifying and Prioritizing Assets”The process of discovering, recognizing, and documenting assets is the first step in risk identification.
Risk identification is essential because the risk that is identified can be assessed and subjected to appropriate mitigation. When assets are not identified, management cannot adequately evaluate, prevent, or minimize cyber risk that can damage both Safire and Safire’s customers whose private information may be revealed and/or stolen for illicit purposes.
Safire will create a list of all information assets.
Information assets may include tangible items such as servers and workstations and non-tangible digital assets such as sensitive data, NPI, Controlled Unclassified Information (“CUI”), Federal Contract Information (“FCI”), and Personally Identifiable Information (“PII”), as well as people. For each asset, Safire will compile the following information, as applicable:
- Hardware (such as servers, workstations, firewalls, wireless routers, mobile phones, printers, copiers, uninterruptible power supply (UPS), power generators)
- Software (such as operating systems, firmware, Outlook, Adobe Acrobat)
- Applications (such as Exchange, SQL Server, Web servers)
- Cloud providers (such as G Suite, Office 365, Amazon AWS)
- Asset ‘owner’ or, in the case of an individual, their manager
- Role/person assigned to maintain the asset
- The nature of the information handled by the asset (e.g., CUI, FCI, PII, PHI, customer data, etc.)
Safire will define a standard for determining the importance of each asset. An overall asset’s monetary value may take into account replacement costs, profitability, and legal or regulatory importance. Once Safire has defined a standard, it will be formally incorporated into the Risk Assessment process.
Identify Threats
Section titled “Identify Threats”Threats are anything that could cause harm to Safire. Every Risk Assessment will likely uncover some basic threats. Additional threats found will depend on the size, type of business, and systems used by Safire.
Common threat types include:
-
a. Unauthorized access (malicious or accidental) : This could be from a hacking attack/compromise, malware infection, or insider threat.
-
b. Misuse of information (or privilege) by an authorized user: This could result from unapproved use of data or changes to data made without approval.
-
c. Data leakage or unintentional exposure of information : This could result from permitting the use of unencrypted portable storage devices without restriction, inadequate retention and destruction practices, transmitting NPI unsecured, or accidentally sending sensitive information to the wrong recipient.
-
d. Loss of data : This can happen when an organization does not have adequate backup and recovery processes.
-
e. Disruption of service or productivity: This includes the inability to access resources due to natural disasters such as floods, hurricanes, and pandemics or due to human-made disasters such as hardware failure from outdated hardware or the physical theft of a computer or server, etc.
Safire will identify all possible threats to the security of its information assets and address those threats that have a reasonable likelihood of adversely impacting its business.
Identify Vulnerabilities
Section titled “Identify Vulnerabilities”A vulnerability is a weakness that can enable a threat to harm Safire. Vulnerabilities can be identified through analysis, audit reports, vulnerability assessments, and tabletop exercises.
Examples of threats and corresponding vulnerabilities are:
-
A. Threat : Data leakage or unintentional exposure of information
-
B. Vulnerability : Unencrypted portable storage with sensitive information was stolen
-
A. Threat : Loss of data
-
B. Vulnerability : Backups tapes from last week did not complete
-
A. Threat : Disruption of service or productivity
-
B. Vulnerability : Pandemic prevents access to office
Safire will identify all vulnerabilities and address those vulnerabilities that have a reasonable likelihood of adversely impacting its business as stated in Safire’s Vulnerability Management Policy.
Likelihood and Impact
Section titled “Likelihood and Impact”Safire will determine the likelihood and impact of all vulnerabilities by assessing the probability that a vulnerability might actually be exploited and the impact that such an exploitation would have on Safire if the asset is compromised, lost or damaged.
Safire will use the categories:
- a. High (highly probable, with significant economic and reputational damage),
- b. Medium (probable, with moderate impact), and
- c. Low (highly unlikely, with minimal impact) to determine the likelihood of an attack or other adverse event.
Inherent Risk and Risk Escalation
Section titled “Inherent Risk and Risk Escalation”To have a complete view of risk, Safire reviews and considers how to respond in worst-case scenarios should any controls fail. Inherent Risk is the initial risk that exists when an organization has not implemented controls to reduce the likelihood of a threat exploiting a vulnerability or to mitigate a risk event’s severity.
Safire uses the categories High, Medium, and Low to determine inherent risk. Factoring inherent risk determines how Safire prioritizes response efforts, particularly for risks that pose a material impact.
Material Risk
Section titled “Material Risk”Inherent risk assessment allows for the identification of Material Risks. A material risk is a quantitative or qualitative scenario where exposure to danger, harm, or loss results in a material impact (e.g., significant financial impact, potential class action lawsuit, death related to product usage, etc.). All material risks must be documented in the Safire Risk Catalog.
Governance and Escalation
Section titled “Governance and Escalation”Risk handling at Safire is divided by scope and severity:
- Operational Risk: Routine operational risk handling falls within the scope of the Chief Operating Officer (COO).
- Enterprise Risk: Broader enterprise risk escalation falls within the scope of the Chief Executive Officer (CEO).
To ensure appropriate oversight, Material Risks, Risk Acceptance Decisions (formally accepting a risk without mitigation), and Unresolved Findings (open issues from audits or assessments) may be escalated directly to the CEO.
Analyze Controls
Section titled “Analyze Controls”Cybersecurity controls are the countermeasures that Safire will implement to detect, prevent, reduce, or counteract security risks. They are the measures that a business deploys to manage threats targeting computer systems and networks. Safire will analyze cybersecurity controls to minimize or eliminate the probability that a threat will exploit a vulnerability. Controls can either be technical or non-technical.
- Non-technical controls are management and operational controls, such as administrative policies, procedures, and standards.
- Technical controls are safeguards that are incorporated into computer hardware, software, or firmware. Encryption, Multi-Factor Authentication (MFA), and firewalls are common technical controls.
Safire shall identify controls that will prevent, mitigate, detect, or compensate for addressing an identified vulnerability.
Determine Control Effectiveness/Residual Risk
Section titled “Determine Control Effectiveness/Residual Risk”Once Safire has identified controls that will prevent, mitigate, detect, or compensate for addressing an identified vulnerability, Safire will assess the control’s effectiveness to determine residual risk. Safire will categorize a control’s effectiveness as Satisfactory, Satisfactory with Recommendations, Needs Improvement, or Inadequate.
A certain amount of Residual Risk will remain in place even after Safire implements security measures and controls. Safire will use the categories High, Medium, and Low to assess the remaining risk once controls have been applied.
Document Risk Assessment Results
Section titled “Document Risk Assessment Results”Safire is to record results in order to make appropriate decisions with respect to strategic planning, budget, policies, procedures, and other matters. Safire’s recorded results will identify assets and describe the corresponding threats and vulnerabilities to derive risk value representing the company’s inherent risk. Safire’s recorded findings also will identify and assess the effectiveness of the set of controls or control recommendations to determine the residual risk to the company.
Risk Assessments are a fundamental part of a risk management process because they help Safire arrive at an acceptable level of risk and draw attention to potential or required control measures. The Risk Assessment process is iterative and must be conducted and reviewed regularly to ensure the Cybersecurity Program’s relevancy.
Sample Risk Assessment
Section titled “Sample Risk Assessment”Asset: Workstations
Section titled “Asset: Workstations”-
Threat: Malware
-
Vulnerability: Phishing E-mail
-
Impact: High
-
Likelihood: High
-
Inherent Risk: High
-
Controls: Training, Anti-virus
-
Control Effectiveness: Satisfactory
-
Residual Risk: Medium
Asset: Firewall
Section titled “Asset: Firewall”-
Threat: Configuration
-
Vulnerability: Misconfigured Firewall
-
Impact: High
-
Likelihood: Medium
-
Inherent Risk: Medium
-
Controls: Change Control
-
Control Effectiveness: Satisfactory
-
Residual Risk: Low
Compliance
Section titled “Compliance”Compliance Measurement
Section titled “Compliance Measurement”The policy owner will verify compliance through methods such as business tool reports and internal and external audits. The CISO, IT, and Compliance functions maintain oversight and will escalate material incidents of non-compliance to the CEO.
Exceptions
Section titled “Exceptions”Any exceptions must be approved by the Policy Owner in advance.
Non-Compliance
Section titled “Non-Compliance”An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Related Standards, Policies, Plans, and Procedures
Section titled “Related Standards, Policies, Plans, and Procedures”- Vulnerability Management Policy
- SSP Hardware Inventory List
- SSP Software Inventory List
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)