Back to Cybersecurity

Capstone Report · Risk Management

Information Risk Management Plan

A full information risk management plan built on the ISO/IEC 27005 process and NIST SP 800-30 — asset inventory with CIA categorization, a scored risk register, a layered risk treatment plan, and security governance. Case study modeled on a large enterprise technology corporation.

Written by Nishan Singh — cybersecurity diploma student

Academic exercise modeled on a large enterprise — illustrative, fictional data. Shared as a study reference from defensive-security coursework.

Executive summary

This plan applies the full risk-management cycle to a large enterprise technology corporation that operates enterprise HR systems, proprietary AI research environments, cloud services, and a fleet of corporate endpoints used by HR, Finance, and Software Development staff. At this scale, a single security failure can expose sensitive employee data, compromise valuable intellectual property, and cross multiple legal jurisdictions.

Using the ISO/IEC 27005 risk process supported by NIST SP 800-30, the plan inventories six critical assets, rates each against the CIA triad, and assesses the major risks in a scored risk register. The most serious are ransomware / credential compromise on core systems, endpoint phishing and malware, ransomware reaching backups, and insider misuse or corporate espionage against AI research data. Before treatment, overall exposure is High; after layered controls, residual risk falls to Low–Medium.

Part 1 — Assets & CIA categorization

Six critical assets, each rated for Confidentiality / Integrity / Availability. The overall rating equals the highest of the three CIA dimensions.

IDAssetC / I / AKey driver
AST-001Employee Master RecordsH / H / MSalaries, banking, tax IDs (PIPEDA)
AST-002Workday HRISH / H / HCentral personnel repository
AST-003HR Coordinator LaptopsH / L / MEncryption if lost or stolen
AST-004Finance Management LaptopsH / L / MFinancial reports, ERP access
AST-005AI Research DataH / H / HProprietary IP and models
AST-006Software Developer PCsH / H / HSource code

Part 2 — Risk register (before & after treatment)

Each risk is scored as Likelihood × Impact (1–5 scale). Every major risk drops to Low–Medium after the treatment controls are applied.

IDRiskInitialResidualOwner
R-01Ransomware / credential stuffing (core platform)20 · High6 · MediumHead of IT & Security
R-02Endpoint phishing & malware16 · High4 · LowEndpoint Admin
R-03Ransomware reaching backups15 · High3 · LowInfrastructure Lead
R-04Physical intrusion (server room)9 · Medium2 · LowFacility Manager
R-05Social engineering (support portal)9 · Medium2 · LowHelpdesk Manager

Part 3 — Risk treatment (defence in depth)

Every risk gets three layers of defence — preventive, detective, and corrective — each control mapped to a recognized framework.

Preventive

Stop it happening

MFA / SSO · RBAC · patching · full-disk encryption · immutable backups · network segmentation · allowlisting

Detective

Spot it quickly

SIEM · EDR · UEBA · ransomware / abnormal-file detection · DLP alerts · email-gateway alerts

Corrective

Recover from it

Isolate & restore from backup · session termination · incident response · monthly restore tests · cyber-insurance

Part 4 — Standards & governance

Controls are mapped to established security standards, with CISO-led governance and compliance to Canadian privacy law (PIPEDA and FOIPPA / FIPPA).

ISO/IEC 27005ISO/IEC 27001 / 27002NIST SP 800-30NIST SP 800-53NIST CSFCIS ControlsPIPEDAFOIPPA / FIPPA

Read the full plan

The complete report and the management briefing are available to download.