Capstone Report · Risk Management
Information Risk Management Plan
A full information risk management plan built on the ISO/IEC 27005 process and NIST SP 800-30 — asset inventory with CIA categorization, a scored risk register, a layered risk treatment plan, and security governance. Case study modeled on a large enterprise technology corporation.
Academic exercise modeled on a large enterprise — illustrative, fictional data. Shared as a study reference from defensive-security coursework.
Executive summary
This plan applies the full risk-management cycle to a large enterprise technology corporation that operates enterprise HR systems, proprietary AI research environments, cloud services, and a fleet of corporate endpoints used by HR, Finance, and Software Development staff. At this scale, a single security failure can expose sensitive employee data, compromise valuable intellectual property, and cross multiple legal jurisdictions.
Using the ISO/IEC 27005 risk process supported by NIST SP 800-30, the plan inventories six critical assets, rates each against the CIA triad, and assesses the major risks in a scored risk register. The most serious are ransomware / credential compromise on core systems, endpoint phishing and malware, ransomware reaching backups, and insider misuse or corporate espionage against AI research data. Before treatment, overall exposure is High; after layered controls, residual risk falls to Low–Medium.
Part 1 — Assets & CIA categorization
Six critical assets, each rated for Confidentiality / Integrity / Availability. The overall rating equals the highest of the three CIA dimensions.
| ID | Asset | C / I / A | Key driver |
|---|---|---|---|
| AST-001 | Employee Master Records | H / H / M | Salaries, banking, tax IDs (PIPEDA) |
| AST-002 | Workday HRIS | H / H / H | Central personnel repository |
| AST-003 | HR Coordinator Laptops | H / L / M | Encryption if lost or stolen |
| AST-004 | Finance Management Laptops | H / L / M | Financial reports, ERP access |
| AST-005 | AI Research Data | H / H / H | Proprietary IP and models |
| AST-006 | Software Developer PCs | H / H / H | Source code |
Part 2 — Risk register (before & after treatment)
Each risk is scored as Likelihood × Impact (1–5 scale). Every major risk drops to Low–Medium after the treatment controls are applied.
| ID | Risk | Initial | Residual | Owner |
|---|---|---|---|---|
| R-01 | Ransomware / credential stuffing (core platform) | 20 · High | 6 · Medium | Head of IT & Security |
| R-02 | Endpoint phishing & malware | 16 · High | 4 · Low | Endpoint Admin |
| R-03 | Ransomware reaching backups | 15 · High | 3 · Low | Infrastructure Lead |
| R-04 | Physical intrusion (server room) | 9 · Medium | 2 · Low | Facility Manager |
| R-05 | Social engineering (support portal) | 9 · Medium | 2 · Low | Helpdesk Manager |
Part 3 — Risk treatment (defence in depth)
Every risk gets three layers of defence — preventive, detective, and corrective — each control mapped to a recognized framework.
Preventive
Stop it happening
MFA / SSO · RBAC · patching · full-disk encryption · immutable backups · network segmentation · allowlisting
Detective
Spot it quickly
SIEM · EDR · UEBA · ransomware / abnormal-file detection · DLP alerts · email-gateway alerts
Corrective
Recover from it
Isolate & restore from backup · session termination · incident response · monthly restore tests · cyber-insurance
Part 4 — Standards & governance
Controls are mapped to established security standards, with CISO-led governance and compliance to Canadian privacy law (PIPEDA and FOIPPA / FIPPA).
Read the full plan
The complete report and the management briefing are available to download.