Files
old-riskletpy/risks.csv
2025-02-07 13:22:17 +01:00

13 KiB

1Risk IDCategoryRisk NamePrimary ImpactSecondary ImpactTertiary ImpactDetection DifficultyRecovery ComplexityBusiness Impact Severity
21StaffingLack of Sufficient IT/Security StaffingDelayed incident responseSecurity control degradationIncreased staff burnoutLowHighHigh
32InfrastructureSingle Points of Failure in InfrastructureService disruptionBusiness continuity impactRecovery delaysMediumHighCritical
43InfrastructureAging Infrastructure RisksSystem instabilitySupport limitationsPerformance degradationMediumHighHigh
54SystemsLegacy Operating Systems and ApplicationsSecurity vulnerabilitiesCompatibility issuesSupport limitationsMediumHighHigh
65SecuritySSL Certificate Private Key ExposureData interceptionTrust violationCompliance breachHighMediumCritical
76SecurityDDoS AttackService unavailabilityRevenue lossReputation damageLowMediumHigh
87CloudMisconfigured Cloud ServicesData exposureUnauthorized accessCompliance violationMediumMediumCritical
98DataAccidental Data DisclosureInformation leakageCompliance violationReputation damageLowMediumHigh
109Source CodeSource Code ExposureIP theftSecurity vulnerability exposureCompetitive disadvantageHighHighCritical
1110EndpointUnapproved Software InstallationMalware riskSystem instabilityCompliance violationMediumLowMedium
1211AccessInsider Privilege EscalationUnauthorized accessData theftSystem compromiseHighMediumHigh
1312MalwareCommodity/Drive-by MalwareSystem infectionData theftResource consumptionLowMediumMedium
1413Supply ChainThird Party Code CompromiseSystem compromiseData theftTrust violationHighHighCritical
1514SecurityDeveloper Spear PhishingCode base compromiseProduct infectionCustomer impactHighHighCritical
1615SecurityBack-office User PhishingCredential theftFinancial fraudSystem compromiseMediumMediumHigh
1716PhysicalUnauthorized Physical AccessAsset theftData exposureSystem compromiseLowMediumHigh
1817EndpointDeveloper Laptop Loss/TheftData exposureCredential compromiseSystem access riskLowMediumHigh
1918MalwareRansomware InfectionData encryptionBusiness disruptionFinancial impactMediumHighCritical
2019SecurityWeb-facing Vulnerability ExploitationSystem compromiseData theftService disruptionMediumHighHigh
2120InfrastructureCloud Provider Service OutageService disruptionRevenue lossCustomer impactLowHighCritical
2221DataDatabase CorruptionData integrity lossService disruptionRecovery effortMediumHighHigh
2322BackupMisconfigured Backup SystemsData loss riskRecovery failureCompliance impactMediumHighCritical
2423NetworkNetwork Segmentation FailureSecurity zone breachLateral movement riskCompliance violationHighMediumHigh
2524APIAPI Gateway CompromiseUnauthorized accessData exposureService manipulationHighHighCritical
2625AccessCompromised Service AccountSystem access breachPrivilege escalationAudit corruptionHighMediumHigh
2726IdentityFailed Identity ProviderAuthentication failureService disruptionProductivity lossLowHighCritical
2827InfrastructureExpired Domain Controller CertificatesAuthentication failureService disruptionBusiness impactLowMediumHigh
2928AccessPrivilege CreepExcessive accessCompliance violationSecurity riskMediumMediumMedium
3029SecurityCompromised Password ManagerCredential exposureMultiple system riskExtended compromiseHighHighCritical
3130DevOpsCI/CD Pipeline CompromiseCode integrity breachMalicious deploymentCustomer impactHighHighCritical
3231Supply ChainDependency Supply Chain AttackSystem compromiseWidespread impactDetection evasionHighHighCritical
3332DevelopmentDevelopment Environment CompromiseSource code theftBuild corruptionIP lossHighHighCritical
3433ContainerContainer Image CompromiseProduction infectionLateral movementData theftHighHighHigh
3534Source CodeCode Repository BreachIP theftSecret exposureDevelopment impactHighHighCritical
3635NetworkBGP Route HijackingTraffic redirectionData interceptionService disruptionHighHighCritical
3736NetworkVPN Concentrator FailureRemote access lossSecurity bypass riskProductivity impactLowMediumHigh
3837NetworkDNS Cache PoisoningTraffic misdirectionData interceptionTrust violationHighMediumHigh
3938EmailEmail Gateway FailureCommunication disruptionSecurity exposureBusiness impactLowMediumHigh
4039NetworkWireless Network CompromiseUnauthorized accessData interceptionNetwork breachMediumMediumHigh
4140StorageStorage Array FailureData unavailabilityService disruptionBusiness impactLowHighCritical
4241SecurityEncryption Key LossData inaccessibilityRecovery impossibilityBusiness impactMediumHighCritical
4342DataData Classification ErrorInappropriate accessCompliance violationSecurity exposureMediumMediumHigh
4443StorageArchive System FailureCompliance violationLegal impactData retention failureMediumHighHigh
4544DataUnauthorized Data TransferData leakageCompliance violationRegulatory impactHighMediumHigh
4645ChangeChange Control BypassSystem instabilitySecurity bypassAudit violationMediumMediumHigh
4746ConfigurationCMDB CorruptionAsset tracking failureAudit impactSecurity planningMediumHighMedium
4847AutomationAutomated Provisioning FailureResource allocationService delaySecurity bypassMediumMediumMedium
4948SecuritySecurity Tool MisconfigurationDetection failureAlert floodingControl effectivenessMediumMediumHigh
5049SecurityPolicy Enforcement Point FailureControl bypassCompliance violationSecurity gapMediumMediumHigh
5150VendorVendor Remote Access CompromiseUnauthorized accessSystem compromiseTrust violationHighHighHigh
5251CloudCloud Service Provider API ChangeIntegration failureService disruptionDevelopment impactMediumMediumHigh
5352VendorManaged Service Provider BreachMultiple client impactData exposureTrust violationHighHighCritical
5453Supply ChainThird Party Software Update CompromiseSystem infectionTrust violationWide impactHighHighCritical
5554VendorVendor Bankruptcy/ClosureSupport lossSecurity gapMigration requirementLowHighHigh
5655PhysicalData Center Power EventService disruptionHardware damageData corruptionLowHighCritical
5756PhysicalNatural Disaster ImpactInfrastructure damageService disruptionBusiness impactLowHighCritical
5857PhysicalHVAC System FailureHardware riskSystem instabilityPerformance impactLowMediumHigh
5958PhysicalFire Suppression System DischargeHardware damageService disruptionRecovery effortLowHighCritical
6059PhysicalPhysical Security System FailureUnauthorized accessAsset riskCompliance violationMediumMediumHigh
6160ComplianceAudit Finding Non-remediationRegulatory penaltyCertification lossLegal exposureMediumHighHigh
6261CompliancePrivacy Regulation ViolationFinancial penaltyReputation damageLegal exposureMediumHighCritical
6362ComplianceData Sovereignty ViolationRegulatory penaltyLegal exposureService restrictionMediumHighHigh
6463ComplianceExport Control ViolationLegal penaltyBusiness restrictionRegulatory impactMediumHighHigh
6564ComplianceLicense Compliance ViolationFinancial penaltyLegal exposureVendor impactMediumMediumHigh
6665Emerging TechAI Model PoisoningDecision corruptionService degradationRecovery effortHighHighHigh
6766Emerging TechQuantum Computing ThreatEncryption riskAuthentication riskSecurity model impactHighHighCritical
6867IoTIoT Device CompromiseNetwork breachData collectionControl system riskHighMediumHigh
6968BlockchainSmart Contract VulnerabilityFinancial lossTransaction manipulationSystem integrityHighHighHigh
7069Network5G Infrastructure ExploitationCommunication compromiseData interceptionService disruptionHighHighHigh
7170AuthenticationPassword Hash LeakCredential compromiseMultiple system riskExtended exposureHighHighCritical
7271AuthenticationOAuth Token ExposureAPI compromiseService impersonationData breachHighMediumHigh
7372AuthenticationSession Token HijackingAccount takeoverUnauthorized accessTransaction fraudHighMediumHigh
7473AuthenticationSAML Certificate ExpirationSSO failureService disruptionBusiness impactLowMediumHigh
7574IdentityDirectory Service Sync FailureAccount issuesAccess control gapUser managementMediumMediumHigh
7675CloudContainer Orchestration Platform CompromiseWorkload manipulationResource theftMulti-tenant impactHighHighCritical
7776CloudCloud Storage Bucket EnumerationData discoveryPrivacy breachCompliance violationMediumMediumHigh
7877CloudServerless Function InjectionCode executionResource theftService manipulationHighHighHigh
7978CloudCloud IAM Role MisconfigurationExcessive permissionsResource exposurePrivilege escalationMediumMediumHigh
8079NetworkCloud Network ACL BypassUnauthorized accessSecurity breachData exposureHighMediumHigh
8180SecuritySIEM System FailureAlert lossDetection gapCompliance violationMediumHighCritical
8281SecurityLog Aggregation System OverflowData lossDetection gapCompliance violationMediumMediumHigh
8382SecuritySecurity Tool Alert FatigueMissed detectionResponse delayControl effectivenessMediumMediumHigh
8483SecurityMonitoring System False PositivesResource wasteResponse delayDetection accuracyMediumLowMedium
8584NetworkNetwork Sensor Blind SpotsVisibility gapDetection evasionInvestigation limitHighMediumHigh
8685APIAPI Rate Limiting BypassResource exhaustionService disruptionCost impactMediumLowMedium
8786APIGraphQL Query Depth AttackResource consumptionService degradationPerformance impactHighMediumHigh
8887WebWeb Application Cache PoisoningContent manipulationUser impactService integrityHighMediumHigh
8988WebClient-Side Template InjectionData theftUser manipulationContent integrityHighMediumHigh
9089WebService Worker HijackingTraffic interceptionContent manipulationCredential theftHighMediumHigh
9190DatabaseDatabase Connection Pool ExhaustionService unavailabilityTransaction failurePerformance impactMediumMediumHigh
9291DatabaseTime-Series Database OverflowData lossAnalysis impactStorage exhaustionMediumMediumHigh
9392DatabaseDatabase Replication LagData inconsistencyRead errorsApplication impactMediumMediumHigh
9493DatabaseNoSQL InjectionData manipulationUnauthorized accessService disruptionHighHighHigh
9594DatabaseDatabase Schema PoisoningData integrityApplication errorsService disruptionHighHighCritical
9695NetworkSDN Controller CompromiseNetwork manipulationTraffic redirectionWide impactHighHighCritical
9796NetworkLoad Balancer Configuration DriftService disruptionPerformance impactAvailability issuesMediumMediumHigh
9897NetworkNetwork Device Firmware CompromiseTraffic manipulationSecurity bypassPerformance impactHighHighCritical
9998SecuritySSL/TLS Version DeprecationService incompatibilitySecurity weaknessCompliance violationLowMediumHigh
10099NetworkNetwork Time Protocol AttackTime sync issueCertificate validationAuthentication issueHighMediumHigh
101100DevOpsInfrastructure as Code Template PoisoningResource misconfigSecurity bypassDeployment pollutionHighHighCritical
102101ContainerContainer Base Image CompromiseWidespread infectionBuild pollutionDevelopment impactHighHighCritical
103102DevOpsArtifact Repository CompromiseBuild corruptionDeployment pollutionDevelopment impactHighHighCritical
104103DevOpsDevelopment Tool Chain BreachCode manipulationBuild corruptionDeployment riskHighHighCritical
105104ConfigurationConfiguration Management Tool CompromiseSystem misconfigSecurity bypassWide impactHighHighCritical
106105MobileMobile Device Management BypassPolicy enforcementData protectionCompliance violationMediumMediumHigh
107106EndpointEndpoint Protection FailureMalware exposureSystem compromiseData theftMediumHighHigh
108107MobileBYOD Policy ViolationData exposureNetwork riskCompliance violationMediumMediumMedium
109108Remote AccessRemote Desktop Protocol ExposureUnauthorized accessSystem compromiseLateral movementHighHighHigh
110109EndpointLocal Administrator Rights AbuseSystem compromiseMalware installationSecurity bypassMediumMediumHigh
111110BusinessAutomated Payment System CompromiseFinancial lossTransaction fraudBusiness impactHighHighCritical
112111BusinessBusiness Email CompromiseFinancial fraudData theftRelationship damageHighHighCritical
113112DocumentDocument Management System BreachInformation disclosureIP theftCompliance violationHighHighHigh
114113BusinessCustomer Support System CompromiseData exposureService manipulationTrust violationHighHighHigh
115114HRHR System Data BreachPersonal data exposureLegal liabilityEmployee trustHighHighCritical
116115AIMachine Learning Model ExtractionIP theftCompetitive lossService replicationHighHighHigh
117116AIDeep Fake Authentication BypassIdentity fraudAccess control bypassTrust violationHighHighHigh
118117Edge ComputingEdge Computing Node CompromiseData exposureService manipulationNetwork breachHighHighHigh
119118IoTDigital Twin ManipulationDecision impactOperational disruptionSafety riskHighHighHigh
120119SecurityZero-Trust Architecture BypassSecurity model failureAccess control bypassTrust violationHighHighCritical