DISPulseGRC ModulesRisk Register
SO

Risk Register

ISO 31000-aligned security risk management with treatment plans and review workflow.

12Total
1Extreme
9High
2Medium
0Low
0Overdue

Risk Heat Map

5×5 likelihood vs consequence matrix

low
medium
high
extreme
Almost Certain
Likely
Possible
Unlikely
Rare
·
·
·
·
·
·
·
1
2
1
·
·
1
4
1
·
·
·
1
1
·
·
·
·
·
InsignificantMinorModerateMajorCatastrophic
RiskCategoryInherentResidualTreat.ActionsReview

Inadequate Security Governance

Lack of formal security governance structure leading to non-compliance with DISP requirements and potential loss of membership.

GovernanceHighMediummitigate
0%
2026-08-12

Security Risk Assessment Gaps

Failure to identify and assess security risks leading to unmitigated threats to Defence information.

GovernanceMediumLowmitigate
0%
2026-08-12

Personnel Security Awareness Gaps

Personnel unaware of security obligations leading to inadvertent disclosure or mishandling of Defence information.

PersonnelHighLowmitigate
0%
2026-08-12

Inadequate Incident Response

Inability to detect, respond to, and report security incidents within the 24-hour DISP requirement.

GovernanceHighHighmitigate
0%
2026-08-12

Insider Threat

Personnel with access to Defence information acting maliciously or being compromised by external actors.

PersonnelHighMediummitigate
0%
2026-08-12

Unauthorised Physical Access

Unauthorised persons gaining access to areas where Defence information is stored or processed.

PhysicalHighMediummitigate
0%
2026-08-12

Ransomware / Malware Attack

Ransomware or malware compromising systems containing Defence information, causing data loss or exfiltration.

ICT/CyberExtremeHighmitigate
0%
2026-08-12

Credential Compromise / Phishing

User credentials compromised through phishing or social engineering, enabling unauthorised access.

ICT/CyberHighMediummitigate
0%
2026-08-12

Data Loss / Backup Failure

Loss of Defence information due to system failure, accidental deletion, or backup inadequacy.

ICT/CyberHighMediummitigate
0%
2026-08-12

Unpatched Systems

Exploitation of known vulnerabilities in unpatched applications or operating systems.

ICT/CyberHighMediummitigate
0%
2026-08-12

Supply Chain Compromise

Subcontractor or supplier security failure exposing Defence information or introducing vulnerabilities.

Supply ChainHighMediummitigate
0%
2026-08-12

Business Continuity Failure

Inability to maintain Defence operations during a disruption (natural disaster, pandemic, key person loss).

OperationalMediumMediummitigate
0%
2026-08-12