View on GitHub

oisru

Repository for the Open Information Security Risk Universe

Severity Risk Factors

Severity risk factors are relevant to the estimation of therange and severity of consequences that a risk event may cause to occur.

External Severity Risk Factors

External Severity Risk Factors are risk factors that are outside of your scope of control that may affect the consequences of the risks you manage.

These are stated as questions to ask yourself or your organisation. The ability to estimate or measure these risk factors will vary between organisations.

Internal Severity Risk Factors

Internal Severity Risk Factors are risk factors that are within your scope of control and that may affect the consequences of the risks you manage. These are factors that can be subject to an internal control.