Identify
Identify business processes, systems, information, users, infrastructure, and third-party dependencies.
PROJECT 01 / RISK MANAGEMENT
A simulated enterprise cybersecurity risk assessment demonstrating how assets, threats, vulnerabilities, business impact, existing controls, inherent risk, residual risk, and risk treatment decisions can be documented and communicated.
01 / EXECUTIVE SUMMARY
The fictional organization used in this assessment relies on cloud services, employee endpoints, enterprise identity, business applications, third-party providers, and centralized security infrastructure.
The objective is to identify cybersecurity scenarios that could negatively affect the confidentiality, integrity, or availability of critical business services and information.
Each scenario is evaluated for likelihood and business impact. Existing safeguards are then considered to estimate residual risk and determine an appropriate treatment strategy.
This project uses simulated organizational information and does not contain confidential information from a current or former employer.
02 / METHODOLOGY
A simplified qualitative 5 × 5 methodology is used for this portfolio exercise. Likelihood and impact are scored from 1 through 5 and multiplied to produce a risk score.
Identify business processes, systems, information, users, infrastructure, and third-party dependencies.
Identify credible threats, vulnerabilities, and risk scenarios affecting organizational assets.
Estimate likelihood and business impact to determine inherent risk before considering controls.
Review preventive, detective, and corrective safeguards that reduce likelihood or impact.
Estimate the remaining exposure after existing safeguards and compensating controls are considered.
Determine whether the risk should be mitigated, accepted, transferred, or avoided.
03 / RISK MATRIX
Risk Score = Likelihood × Impact. The matrix provides a consistent method for prioritizing risk scenarios for treatment and escalation.
04 / IDENTIFIED RISKS
The register translates technical cybersecurity scenarios into business risks that can be prioritized, assigned, treated, and monitored.
| ID | Risk Scenario | L | I | Score | Inherent | Key Controls | Residual | Treatment |
|---|---|---|---|---|---|---|---|---|
| R-001 | Privileged account compromise | 4 | 5 | 20 | Critical | MFA, RBAC, PAM, logging | Medium | Mitigate |
| R-002 | Exploitation of an unpatched internet-facing system | 4 | 4 | 16 | Critical | Scanning, patching, configuration management | Medium | Mitigate |
| R-003 | Successful phishing attack leading to account compromise | 4 | 4 | 16 | Critical | Email filtering, MFA, awareness training | Medium | Mitigate |
| R-004 | Sensitive information exposed through a third-party provider | 3 | 5 | 15 | Critical | Vendor assessment, contractual requirements, monitoring | High | Mitigate / Transfer |
| R-005 | Excessive employee access to sensitive business systems | 3 | 4 | 12 | High | RBAC, least privilege, periodic access reviews | Medium | Mitigate |
| R-006 | Insufficient security logging delays detection and response | 3 | 3 | 9 | High | SIEM, centralized logging, alerting | Medium | Mitigate |
05 / SAMPLE FINDING
Enterprise identity and privileged administration environment
Credential theft, phishing, session theft, or account takeover
Excessive privileged access, weak authentication controls, or insufficient monitoring
Unauthorized system access, sensitive data exposure, service disruption, and compliance impact
Likelihood 4 × Impact 5 = Score 20 / Critical
Mitigate
With stronger authentication, privileged access management, least privilege, recurring reviews, and centralized monitoring, the likelihood of successful misuse is reduced. The potential impact remains significant because of the sensitivity of privileged access.
06 / CONTROL MAPPING
The sample privileged-access finding can be connected to established cybersecurity control families and risk-management outcomes.
Protect outcomes involving identity management, authentication, and access control.
AC-2 Account Management and AC-6 Least Privilege.
IA-2 Identification and Authentication.
Access Control Management.
PROJECT CONCLUSION
This portfolio project demonstrates how cybersecurity issues can be converted into structured business risks, evaluated using consistent criteria, mapped to security controls, and communicated through actionable remediation recommendations.