THREAT AGENT
FACTORS
Skill level
0 - N/A
1 - No Technical Skills
2 - N/A
3 - Some Technical Skills
4 - N/A
5 - Advanced Computer User
6 - Network And Programming Skills
7 - N/A
8 - N/A
9- Security Penetration Skills
Motive
0 - N/A
1 - Low Or No Reward
2 - N/A
3 - N/A
4 - Possible Reward
5 - N/A
6 - N/A
7 - N/A
8 - N/A
9- High Reward
Opportunity
0 - Full Access/Expensive Resources Required
1 - N/A
2 - N/A
3 - N/A
4 - Special Access Or Resources Required
5 - N/A
6 - N/A
7 - Some Access Or Resources Required
8 - N/A
9 - No Access Or Resources Required
Size
0 - N/A
1 - N/A
2 - Developers or System Administrators
3 - N/A
4 - Intranet Users
5 - Partners
6 - Authenticated Users
7 - N/A
8 - N/A
9 - Anonymous Internet Users
Threat Agent Score
0
VULNERABILITY
FACTORS
Ease of Discovery
0 - N/A
1 - Practically impossible
2 - N/A
3 - Difficult
4 - N/A
5 - N/A
6 - N/A
7 - Easy
8 - N/A
9 - Automated Tools available
Ease of Exploit
0 - N/A
1 - Theoretical
2 - N/A
3 - Difficult
4 - N/A
5 - Easy
6 - N/A
7 - N/A
8 - N/A
9 - Automated Tools available
Awareness
0 - N/A
1 - Unknown
2 - N/A
3 - N/A
4 - Hidden
5 - N/A
6 - Obvious
7 - N/A
8 - N/A
9 - Public Knowledge
Intrusion Detection
0 - N/A
1 - Active Detection In Application
2 - N/A
3 - N/A
4 - Logged And Reviewed
5 - N/A
6 - N/A
7 - N/A
8 - Logged Without Review
9 - Not Logged
Vulnerability Score
0
Likelihood Score
0
TECHNICAL IMPACT
FACTORS
Loss of Confidentiality
0 - N/A
1 - N/A
2 - Minimal non-sensitive data disclosed
3 - N/A
4 - N/A
5 - N/A
6 - Minimal critical data disclosed or Extensive non-sensitive data disclosed
7 - Extensive critical data disclosed
8 - N/A
9 - All Data Disclosed
Loss of Integrity
0 - N/A
1 - Minimal Slightly Corrupt Data
2 - N/A
3 - Minimal Seriously Corrupt Data
4 - N/A
5 - Extensive Slightly Corrupt Data
6 - N/A
7 - Extensive Seriously Corrupt Data
8 - N/A
9 - All Data Totally Corrupt
Loss of Availability
0 - N/A
1 - Minimal Secondary Services Interrupted
2 - N/A
3 - N/A
4 - N/A
5 - Minimal Primary or Extensive Secondary Services Interrupted
6 - N/A
7 - Extensive Primary Services Interrupted
8 - N/A
9 - All Services Completely Lost
Loss of Accountability
0 - N/A
1 - Fully Traceable
2 - N/A
3 - N/A
4 - N/A
5 - N/A
6 - N/A
7 - Possibly Traceable
8 - N/A
9 - Completely Anonymous
Technical Impact Score
0
BUSINESS IMPACT
FACTORS
Financial Damage
0 - N/A
1 - Less Than The Cost To Fix The Vulnerability
2 - N/A
3 - Minor Effect On Annual Profit
4 - N/A
5 - N/A
6 - N/A
7 - Significant Effect On Annual Profit
8 - N/A
9 - Bankruptcy
Reputation Damage
0 - N/A
1 - Minimal Damage
2 - N/A
3 - N/A
4 - Loss Of Major Accounts
5 - Loss Of Goodwill
6 - N/A
7 - N/A
8 - N/A
9 - Brand Damage
Non-Compliance
0 - N/A
1 - N/A
2 - Minor Violation
3 - N/A
4 - N/A
5 - Clear Violation
6 - N/A
7 - High Profile Violation
8 - N/A
9 - N/A
Privacy Violation
0 - N/A
1 - N/A
2 - N/A
3 - One Individual
4 - N/A
5 - Hundreds Of People
6 - N/A
7 - Thousands Of People
8 - N/A
9 - Millions Of People
Business Impact Score
0
Impact Score
0
Overall Risk Score
0
Made by
Kunal (Kunull) Walavalkar