Security Risk Register

An interactive tool for identifying, documenting, assessing, treating, and monitoring IT security risks.

Risk Management Cybersecurity CIA Triad JavaScript HTML CSS
● LOCAL APPLICATION Data is stored locally in your browser

Risk Overview

Summary of registered IT security risks.

+ New Risk
TOTAL RISKS 0

Registered risks

HIGH / CRITICAL 0

Risks requiring priority attention

IN PROGRESS 0

Ongoing risk treatment

MITIGATED 0

Mitigated risks

Risk Matrix

Likelihood × Impact

5
5
10
15
20
25
4
4
8
12
16
20
3
3
6
9
12
15
2
2
4
6
8
10
1
1
2
3
4
5
1
2
3
4
5
↑ Likelihood Impact →
Low Medium High Critical

Registered Risks

Overview of identified risks, risk levels, risk owners, and current status.

+

No Risks Registered

Create your first risk assessment to start building the risk register.

Create First Risk

New Risk Assessment

Identify the asset, threat, and vulnerability. Then assess the risk and document how it should be treated.

01 — Identification
System, information, or other resource that needs to be protected.
An event or actor that could cause harm.
A weakness that could be exploited by the threat.
02 — CIA Impact

Assess the potential impact on confidentiality, integrity, and availability.

Confidentiality
Integrity
Availability
03 — Inherent Risk

Assess the risk before the planned security controls have been implemented.

×
=
RISK 9 /25
RISK LEVEL MEDIUM
04 — Risk Treatment

Document how the risk should be treated, who is responsible for it, and which security controls are planned.

Describe the controls intended to reduce the likelihood or impact.
05 — Residual Risk

Assess the expected risk level after the planned security controls have been implemented.

×
=
RISK 6 /25
RESIDUAL RISK LEVEL MEDIUM
06 — Notes

From Security Concepts to a Functional Tool

Security Risk Register is a portfolio and educational project that applies fundamental IT risk management principles in a functional web-based workflow.

01

Identify

Document assets, threats, and vulnerabilities that together can create a risk scenario.

02

Assess

Assess likelihood, impact, and effects on confidentiality, integrity, and availability.

03

Treat

Document risk treatment, security controls, risk ownership, status, and target dates.

04

Monitor

Compare inherent risk with residual risk after planned security controls have been implemented.

Project Technologies

HTML5 CSS JavaScript LocalStorage CSV Export
About This Tool

This is an educational and portfolio tool that demonstrates a simplified workflow for IT risk management. It is not intended to replace an organization's established risk management methodology, security policies, or professional GRC systems.