Beau-Tie

securityiso31000
CausesRisk eventImpacts
Cause: Phishing of staff credentials
Phishing of staff credentials
Cause: Unpatched software vulnerability
Unpatched software vulnerability
Impact: Regulatory fines and penalties
Regulatory fines and penalties
Impact: Reputational damage
Reputational damage
Phishing awareness training, preventive control, existing, partially effectivePEmail filtering, preventive control, existing, effectivePMFA rollout, preventive control, planned for 0–3 monthsPPatch management process, preventive control, existing, partially effectivePVulnerability scanning, detective control, existing, effectiveDAutomated patching pipeline, preventive control, planned for 3–6 monthsPBreach notification protocol, corrective control, existing, effectiveCPrivacy compliance program, directive control, existing, highly effectiveDiCrisis communications plan, corrective control, existing, partially effectiveCCustomer notification process, corrective control, existing, effectiveCExternal PR retainer, corrective control, planned for 0–3 monthsCRisk event: Loss of sensitive customer data
Loss of sensitive customer data
Extreme
Moderate

Disabled

Moderate — L5 × C1High — L5 × C2High — L5 × C3Extreme — L5 × C4Extreme — L5 × C5Moderate — L4 × C1Moderate — L4 × C2High — L4 × C3Extreme — L4 × C4Extreme — L4 × C5Low — L3 × C1Moderate — L3 × C2Moderate — L3 × C3High — L3 × C4Extreme — L3 × C5Low — L2 × C1Low — L2 × C2Moderate — L2 × C3High — L2 × C4High — L2 × C5Low — L1 × C1Low — L1 × C2Moderate — L1 × C3Moderate — L1 × C4High — L1 × C5C1C2C3C4C5L5L4L3L2L1RT