# Security Risk Assessment Worksheet

**Organisation / site:** ____________________
**Assessment date:** ____________  **Assessor:** ____________________
**Scope of assessment:** ____________________________________________
**Next review due:** ____________

---

## 1. Assets under assessment

| Asset ID | Asset (people / information / physical / system) | Owner | Criticality (Low/Med/High/Critical) | Classification |
|---|---|---|---|---|
| A-01 | | | | |
| A-02 | | | | |
| A-03 | | | | |

## 2. Threat sources considered

- [ ] Trusted insider (malicious)
- [ ] Trusted insider (unintentional)
- [ ] Issue-motivated group / activism
- [ ] Criminal (opportunistic)
- [ ] Criminal (organised)
- [ ] Foreign intelligence / state actor
- [ ] Cyber intrusion
- [ ] Supply chain compromise
- [ ] Natural hazard / service disruption

## 3. Likelihood and consequence scales

**Likelihood:** 1 Rare · 2 Unlikely · 3 Possible · 4 Likely · 5 Almost certain
**Consequence:** 1 Insignificant · 2 Minor · 3 Moderate · 4 Major · 5 Severe

**Rating matrix (L x C):** 1–4 Low · 5–9 Medium · 10–14 High · 15–25 Extreme

## 4. Risk assessment

| Ref | Asset | Threat | Vulnerability | Existing controls | L | C | Inherent rating | Additional treatment | Owner | Due | Residual rating |
|---|---|---|---|---|---|---|---|---|---|---|---|
| SR-01 | | | | | | | | | | | |
| SR-02 | | | | | | | | | | | |
| SR-03 | | | | | | | | | | | |
| SR-04 | | | | | | | | | | | |

## 5. Control review

| Control domain | In place? | Effectiveness (Effective / Partial / Ineffective) | Evidence | Comment |
|---|---|---|---|---|
| Governance and accountability | | | | |
| Personnel security and screening | | | | |
| Physical security and access control | | | | |
| Information handling and classification | | | | |
| Cyber and system security | | | | |
| Visitor and contractor management | | | | |
| Incident detection and response | | | | |
| Business continuity and recovery | | | | |

## 6. Recommendations and acceptance

| # | Recommendation | Priority | Estimated cost | Decision (Accept / Treat / Defer) | Decision maker | Date |
|---|---|---|---|---|---|---|
| 1 | | | | | | |
| 2 | | | | | | |
| 3 | | | | | | |

**Accountable security executive:** ______________  **Signature:** ______________  **Date:** __________

---
Template provided by Jd Global Quality & Security Solutions Pty Ltd, Canberra.
Adjust scales, domains and thresholds to your own risk appetite and obligations.
