LogESP (c) 2018 Dan Persons | MIT License
The LogESP risk management system is based on the NIST risk assessment guidelines.
A non-adversarial threat event is an event that is not caused intentionally, but could cause harm to an organization (i.e. an earthquake, a configuration mistake).
name
- the event namedesc
- a description of the eventevent_type
- the event typeinfo_source
- the source of information on the threattier
- the information source tier (organization-wide, department-wide, or localized)relevance
- the relevance, or likelihood, of the event- sources - non-adversarial threat sources that could cause the event
- risk conditions - predisposing conditions related to the event
- responses - measures taken in response to the threat
likelihood_initiation
- the likelihood of the event being initiated (scale of 1 to 100)likelihood_impact
- the likelihood of adverse impact if the event is initiated (scale of 1 to 100)- impacts - potential impacts of the event
assigned_risk
- the level of risk assigned to the event (scale of 1 to 100)
A non-adversarial threat source is a person, entity, or occurance that could cause harm to an organization without intent.
name
- the threat source namedesc
- a description of the threat sourceevent_type
- the threat source typeinfo_source
- the source of information on the threat sourcetier
- the information source tier (organization-wide, department-wide, or localized)in_scope
- whether or not the threat source in within the scope of risk managementrange_of_effect
- the threat source's range of effect (scale of 1 to 100)
Risk conditions are predisposing conditions that make a threat event more likely to happen.
name
- the condition namedesc
- a description of the conditionvuln_type
- the condition typeinfo_source
- the source of information on the conditiontier
- the information source tier (organization-wide, department-wide, or localized)pervasiveness
- the vulnerability's level of severity (scale of 1 to 100)
Responses are measures taken to reduce the risk from a threat.
name
- the response namedesc
- a description of the responseresponse_type
- the response typeeffectiveness
- the effectiveness of the response (scale of 1 to 100)status
- the status of the response (enabled, planned, declined, etc)
Impacts are the unwanted results if a threat event were to occur.
name
- the impact namedesc
- a description of the impactimpact_type
- the impact typeinfo_source
- the source of information on the threat sourcetier
- the information source tier (organization-wide, department-wide, or localized)severity
- the impact's level of severity (scale of 1 to 100)impact_tier
- the impact tier (organization-wide, department-wide, or localized)