APPENDIX B

Qualitative Risk Scale Reference Tables

Aspects of the qualitative risk scales are spread throughout several chapters in this book. The following is a consolidated reference for these scales, which can be used in your own assessments:

Table 4.2 Qualitative Risk Sensitivity Scale

Level Criteria
High A compromise would be unacceptable for the organization, resulting in significant monetary, productivity, or reputational losses
The ability to continue normal operations and/or business activity would be greatly impaired, potentially resulting in noncompliance with legal or regulatory requirements and/or loss of public confidence in the organization
Moderate A compromise would be marginally acceptable for the organization, resulting ...

Get Security Risk Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.