Memra

Building a risk register for a home network

◈ 4 cards

Seven columns and defensible numbers. Enumerate the asset before rating it, identify the control that decides the consequence, and derive the level from the matrix instead of asserting it.

The seven columns

A risk register is the output of stage 3 of a detailed analysis, and it has seven columns:

Asset · Threat / vulnerability · Existing controls · Likelihood · Consequence · Level of risk · Risk priority

It is sorted in decreasing order of risk, and every rating in it is backed by written rationale and evidence. Those seven names are not decoration: in an exam they are the structure of your answer, and an answer that produces them in order has already earned the marks for structure before it says anything about the risk itself.

Two failure modes to avoid before we start. First, a register is not a vulnerability list. Unpatched operating system is not a register entry — it is a vulnerability, and it causes no harm on its own. A register entry pairs an asset with a threat that can reach it and carries the harm through to a level. Second, a register is not a system inventory. One asset faces many threats and one threat targets many assets, so the row count has nothing to do with the number of devices.

Enumerate the asset before you rate it

Here is the step that separates a full-marks answer from a half-marks one, and it happens before any number is assigned. Personal and financial data is a category, not an asset. You cannot value a category and you cannot rate the consequence of losing one. So the first thing the entry does is turn it into a list.

Priya is a records officer at Coldstream. Her household network carries three smartphones, two tablets, two laptops, a desktop and a small network-attached storage box that everything backs up to. On those devices sit:

  • tax returns and the receipts supporting them — reconstructible from institutional records, but only slowly, and only if the counterparties still hold them;
  • bank and credit-card statements — re-downloadable from the bank, usually for a limited retention window;
  • payroll and pension records — held by the employer and the scheme too, so recoverable;
  • insurance policies and the mortgage file — the insurer and lender hold originals;
  • saved credentials and two-factor recovery codes — losing these locks the household out of the very services it would use to recover everything above, which makes this the entry with the sharpest ordering effect;
  • scanned identity documents — passports, driving licences, birth certificates; replaceable, at a fee and after weeks;
  • family photographs and videoirreplaceable. There is no counterparty holding a second copy.

Notice that the list is not uniform, and that the non-uniformity is a finding. Six of those seven categories can be reconstructed from someone else's records. One cannot. That single distinction is what carries the consequence rating, and an answer that treats personal and financial data as one undifferentiated blob cannot make it.

The threat, and the controls already in place

Threat: corruption of those files by a worm or virus imported into the household network — through an e-mail attachment, a compromised download, a phone plugged into a work machine, or a family member's device brought home from elsewhere. Vulnerability: consumer endpoints, mixed operating systems, no central administration, and users who are not IT professionals and should not have to be.

Existing controls, honestly stated:

  • operating-system and application auto-update enabled on every device;
  • a reputable anti-malware engine running on the two laptops and the desktop (and, importantly, not on the tablets, where the platform's own sandboxing substitutes for it);
  • an ISP-supplied router doing NAT with default-deny inbound, so nothing reaches these devices unsolicited from the Internet;
  • and backup — which is the one that decides the entry.

The control that decides the consequence

Everything in that list except the last one reduces likelihood. Auto-update closes the vulnerability the worm would use; the anti-malware engine catches the sample; default-deny inbound removes the unsolicited network vector. None of them changes what happens if a worm does execute.

Backup is the only control in the list that touches consequence, and whether it earns that depends entirely on how it is arranged. The NAS is always mounted and writable from every device — which is exactly the arrangement a file-encrypting or file-corrupting worm reaches first. An always-mounted backup is corrupted alongside the originals and buys nothing. A backup that is offline, or versioned and immutable, keeps a clean copy that the worm could not reach.

So the entry has to be written twice, because the answer genuinely differs:

Case A — no offline backup. Likelihood Possible; consequence Major; level Extreme.

Case B — a tested, versioned, offline backup. Likelihood Possible (unchanged — the backup does nothing to stop the worm arriving); consequence Minor; level Low.

That likelihood stayed put while consequence moved four levels is the insight this question is testing. A control changes the rating, and which rating it changes tells you which lever it pulls.

Justifying the two ratings

Likelihood: Possible. Apply the calibration rule. Malware certainly arrives at this household — the mail provider quarantines it, the browser blocks downloads, the phones warn about sideloading. But no infection has ever executed on these devices. There is no prior occurrence, so Likely is unavailable without a further argument, and there is no changed threat environment to supply one. Equally it is not Unlikely: the vector is live, demonstrated weekly, and the controls are consumer-grade and partial. Possible is the honest cell, and the sentence beginning no infection has ever executed here is what makes it defensible.

Consequence: Major, absent an offline backup. Rate it at the household, not at the laptop. The irreplaceable category is gone permanently. The reconstructible categories take weeks of correspondence with a bank, an employer, an insurer and a lender to rebuild — and the credential store that would have made that correspondence easy went with them. Identity documents must be reordered and paid for. The disruption runs to weeks, it requires sustained effort from the people affected, and it is externally visible in the sense that every counterparty has to be contacted. That is Major on the scale. It is not Catastrophic — nobody's livelihood ends — and it is certainly not Doomsday.

With a tested offline backup, the same event costs a restore and an afternoon. Minor.

Level and priority

Read the level from the matrix rather than asserting it, and say you are doing so: Possible × Major falls in the Extreme cell; Possible × Minor falls in Low. The whole point of building the matrix in advance is that this step is mechanical.

Priority is not the level. Priority is the household deciding what to do first, and here the reasoning is that the treatment which moves the entry from Extreme to Low costs one external drive and thirty minutes a month. So this risk is treated first, ahead of risks with the same level and a far larger fix — precisely the reordering the previous lesson warned about, applied in the household's favour rather than against it.

Treatment. Both reduction levers, named as such. Reduce consequence: a versioned, offline backup of the seven file categories, with a restore tested quarterly — an untested backup is a belief, not a control. Reduce likelihood: hold auto-update on, keep the anti-malware engine current on the three general-purpose machines, and stop the household practice of moving files between work and home devices on a USB stick.

AssetThreat /vulnerabilityExistingcontrolsLikel.Conseq.LevelPriorityIntegrityof thehouseholdpersonalandfinancialfiles (7categories,oneirreplaceable)Importedworm orviruscorruptsthem;consumerendpoints,nocentraladminauto-update;anti-malwareon 3 of 8devices;NATdefault-deny;always-mountedNASPossibleMajorExtreme1 — cheapfix,largemovesamesameas above,butbackup isoffline,versionedandrestore-testedquarterlyPossibleMinorLowroutineproceduresSorted by level, then reordered by management judgement — level is not priority.
One asset, one threat, two rows — because one control changed. Likelihood is identical in both rows; only consequence moved, which is how you can tell that backup is a consequence-reducing control and not a likelihood-reducing one.
File categoryWho else holds a copyIf corruptedTax returns and receiptsthe revenue authority; somecounterpartiesslow to rebuildBank and card statementsthe bank, within itsretention windowre-downloadablePayroll and pension recordsemployer and schemeadministratorrecoverableInsurance and mortgage fileinsurer and lender holdoriginalsrecoverableSaved credentials and 2FArecovery codesnobodylocks you out of therecovery routeScanned identity documentsthe issuing authoritiesreplaceable, at a fee, inweeksFamily photographs andvideonobodyirreplaceable — permanentlossA category is not an asset. Enumerate first, then rate.
Do this before you rate anything. Six categories are reconstructible from somebody else’s records and one is not — and that single asymmetry is what the consequence rating turns on.
NORMAL ~/memra/learn/comp-400/building-a-risk-register-for-a-home-network utf-8 LF