12.07.2015 Views

Security Risk Assessment for Transport Operators - Department of ...

Security Risk Assessment for Transport Operators - Department of ...

Security Risk Assessment for Transport Operators - Department of ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Example 5: Rating likelihoodA freight train operator has identified a risk as, ‘The payroll system is affected by acomputer virus, resulting in the loss <strong>of</strong> employee in<strong>for</strong>mation.’While this type <strong>of</strong> attack has never be<strong>for</strong>e happened to the company, attacks have beenseen against other organisations and the government is warning <strong>of</strong> a heightened threatfrom computer viruses against infrastructure operators.Given this in<strong>for</strong>mation and taking onboard security measures that are already in place(‘current controls’), the operator’s risk committee considers that there is a 20 per centchance <strong>of</strong> a computer virus affecting the payroll system, which would result in the loss<strong>of</strong> employee in<strong>for</strong>mation.Using Table 6 on page 18, the likelihood <strong>of</strong> the risk occurring is there<strong>for</strong>e ratedas ‘C’ (possible).*Note: a computer virus can <strong>for</strong>m part <strong>of</strong> a wider targeted cyber attack, as identified in Table 2 on page 11.2.4 Rating riskOnce you have identified the appropriate levels <strong>of</strong> consequence and likelihood <strong>for</strong> the risk, younow need to allocate an overall risk rating. As with both the consequence and likelihood tables,you can alter the risk rating matrix to better represent your organisation’s individual requirements.Use Table 7 to establish the overall level <strong>of</strong> risk by cross referencing the ratings <strong>for</strong> consequenceand likelihood:Table 7: Rating the riskLikelihoodConsequenceInsignificant Minor Moderate Major Catastrophic(1) (2) (3) (4) (5)Almost Certain (A) Significant High High Extreme ExtremeLikely (B) Medium Significant High High ExtremePossible (C) Medium Medium Significant High HighUnlikely (D) Low Medium Medium Significant HighRare (E) Low Low Medium Medium Significant<strong>Security</strong> <strong>Risk</strong> <strong>Assessment</strong> Guide 19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!