You are on page 1of 6

Harmonized Threat Risk Assessment Report Template

https://www.cse-cst.gc.ca/en/system/files/pdf_documents/tra-emr-1-e.pdf

Statement of Sensitivity

Asset Confidentiality Confidentiality Integrity Integrity Availability Availability


Level Reason Level Reason Level Reason

Risk Scenario

Vulnerability Description:

Threat Description:

Threat Agent:

Assets Affected:

How does it affect confidentiality?

Is it affected in Storage?

Is it affected in Transit?

Is it affected in Processing?

How does it affect integrity?


Is it affected in Storage?

Is it affected in Transit?

Is it affected in Processing?

How does it affect availability?

Is it affected in Storage?

Is it affected in Transit?

Is it affected in Processing?

What safeguards are in place or planned to be in place that will reduce the risk?

Threat Assessment (Current Status)

Level Reason
Threat Likelihood
Threat Gravity
Overall Threat

Vulnerability Assessment (Current Status)

Level Reason
Vulnerability Impact on
Probability of Compromise
(Prevention)
Vulnerability Impact on
Severity of Outcome
(Detection, Response, or
Recovery)
Overall Vulnerability

Residual Risk Calculation (Current Status)

Level Numeric Value


Applicable Asset
Classification
Overall Threat
Overall Vulnerability
Residual Risk

Is the Residual Risk Level acceptable?


Recommendation:

Avoid?

Transfer?

Accept?

Reduce?

 Policy and Process:


 Education Training and Awareness:
 Technology:

Risk Assessment After Implementation of Recommendations

Does Statement of Sensitivity Change?

Asset Confidentiality Confidentiality Integrity Integrity Availability Availability


Level Reason Level Reason Level Reason

Threat Assessment (After Recommendation)

Level Reason
Threat Likelihood
Threat Gravity
Overall Threat
Vulnerability Assessment (After Recommendation)

Level Reason
Vulnerability Impact on
Probability of Compromise
(Prevention)
Vulnerability Impact on
Severity of Outcome
(Detection, Response, or
Recovery)

Residual Risk Calculation (After Recommendation)

Level Numeric Value


Applicable Asset
Classification
Overall Threat
Overall Vulnerability
Residual Risk

Is the Residual Risk Level acceptable?

You might also like