Risk Matrix
Ser (a) (b) (c) (d) (e) (f)
1 Probability 10% 15% 25% 50% 100%
2 Threat Capability 5 5 8 10 10
3 Intention 2 3 8 10 10
4 Prob' of V 10% 12% 30% 30% 100%
Vulnerability
5 Scale of V 7 2 5 5 5
6 Impact 5 8 7 5 10
7 RISK RATING: 3.5 4.32 168 375 5000
Rating = Product of Threat x Product of Vulnerability x Impact
Remarks
(f)
Probability of Attack
(10 = Highly Capable, 0 = Incapable)
(10 = Specified intent, 0 = no intent)
(Probability of vulnerability being exploited)
(10 is vulnerable, 0 is invulnerable)
(10 = severe impact, 0 = no impact)
Risk Matrix
Threat
Item
Probability Capability Intention
Ser (a) (b) (c) (d)
1 50% 5 5
2 50% 5 5
3 60% 5 5
4 50% 5 3
5 50% 4 5
6 40% 5 5
7 50% 5 5
8 60% 5 5
9 50% 6 5
10 50% 5 7
11 50% 5 5
12 50% 5 5
13 50% 5 5
Vulnerability
Impact RISK RATING: Risk Ranking
Prob' of V Scale of V
(e) (f) (g) (h) (i)
50% 5 0 0 13
50% 1 5 31.25 12
20% 5 5 75 11
50% 5 5 93.75 10
50% 5 5 125 8
50% 5 5 125 8
50% 5 5 156.25 7
50% 5 5 187.5 5
50% 5 5 187.5 5
50% 5 5 218.75 4
80% 5 5 250 3
50% 9 5 281.25 2
50% 5 10 312.5 1
Quantifying the Unquantifyable
Column Category
(a) Item
(b) Probability
(c) Threat Capability
(d) Intention
(e) Prob' of V
Vulnerability
(f) Scale of V
(g) Impact
(h) RISK RATING:
Quantifying the Unquantifyable
Description
Threat under evaluation
Probability of Attack - Subjective, from observation historic attacks and 'gut feel'
Capability of Aggresor (10 = Highly Capable, 0 = Incapable)
Intent of Agressor (10 = Specified intent, 0 = no clear intent)
Probability of vulnerability being exploited - Subjective, from observation historic attacks and 'gut feel'.
(10 is vulnerable, 0 is invulnerable)
(10 = severe impact, 0 = no impact)
Risk Rating - A Single Number enabling ranking of the risk