Risk Assessment - Separate CIA impact recording

Hey all, I watched the demo from Tuesday (Great Demo, thanks for holding it)

One thing I didn’t see was whether there’s the ability to implement Risk Assessments per the requirements of ISO 27005 e.g. recording separate impact scores for Confidentiality, Integrity, and Availability before using the highest one to calculate the risk score.

Is this possible in Eramba please?

Hi Geoff,

welcome to the forum!

Worth noting is that ISO 27005’s decomposition of impact in CIA is an example technique, more than a requirement.

If you haven’t already, I’d recommend taking a look at the eramba docs regarding risk classifications and calculations: Risk Management in eramba: Implementation Guide

But basically, with eramba’s current risk settings and customizations, you have two main options to achieve the highest-of-CIA-impact:

  1. single matrix + 3 custom fields (preferred):

    Use the standard Likelihood × Impact matrix. Add 3 custom fields to the risk: Impact (C), Impact (I), Impact (A). Score each one during the assessment. Then set the risk’s Impact classification to the highest of the 3. That way you evidence (for 27005) that each dimension was assessed separately, and that the risk value comes from the “worst case”.

  2. multiple matrices

    Go to Settings → Risk Calculation and switch from a single matrix to multiple matrices (multiplication). Then define one impact classification type per dimension: C, I, A. Each pairs with Likelihood. Every risk is assessed 3 times, and you see the 3 scores side by side.

    The “caveat” here is that you get 3 parallel assessments, not an automatic “highest of the 3”. If your methodology says the score is the maximum, we would go with option 1 instead.

Hope this helps to answer your question!

Regards,

Guillermo - eramba

Thanks Guillermo, I appreciate your feedback.

I take your point, but a separate reflection of the impact of C,I, and A has become something of an industry standard and in my experience is largely expected now by External auditors and Certification Bodies.

It would be good if Eramba supported this natively rather than having to manually work around it with extra fields and copying the highest score into the Impact field (giving the chance for mistakes or missing a step). I have no intent of effectively conducting 3 separate risk assessments for each risk.