# Risk Register

> The living risk document – ISO 31000 process + 27001 cl.8.2/8.3
> output. One row per identified risk; review quarterly minimum.

| Field | Value |
|-------|-------|
| Period | YYYY cycle |
| Methodology | DOC-ISMS-010 |
| Owner | Risk committee / CISO |

## Register

| ID | Asset / scope | Risk description | L | I | Score | Level | Treatment | Control (Annex A) | Owner | Residual | Status |
|----|---------------|------------------|---|---|-------|-------|-----------|-------------------|-------|----------|--------|
| R-001 | Customer DB | Unauthorized access to personal data | 3 | 4 | 12 | High | Mitigate | A.8.3 access control | @name | 4 | Treating |
| R-002 | Office | Loss of premises access | 2 | 3 | 6 | Med | Transfer | insurance | @name | 3 | Accepted |
| R-003 | Laptop fleet | Lost device data exposure | 3 | 4 | 12 | High | Mitigate | A.8.1 encryption | @name | 4 | Treating |
| R-004 | SaaS vendor | Vendor outage affects availability | 3 | 3 | 9 | Med | Mitigate | A.5.22 supplier | @name | 6 | Monitor |
| R-005 | – | – | | | | | | | | | |

## Summary statistics

| Level | Count | Target |
|-------|-------|--------|
| Critical/High | N | trending down |
| Medium | N | – |
| Low/accepted | N | – |

## Heat map (L x I)

| I\L | 1 | 2 | 3 | 4 | 5 |
|-----|---|---|---|---|---|
| 5 | | | | | |
| 4 | | | R-001 | R-003 | |
| 3 | | | R-004 | | |
| 2 | | | | | |
| 1 | | | | | |

## Review log

| Date | Change | By |
|------|--------|-----|
| YYYY-MM-DD | R-001 added | @name |
