OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk assessment methodology developed by Carnegie Mellon University's Software Engineering Institute. Unlike compliance-first frameworks that start with a checklist of controls, OCTAVE starts with your most critical information assets and works outward — identifying what threatens them, where the vulnerabilities are, and what controls will actually reduce risk. This guide walks through the practical steps of conducting an OCTAVE Allegro assessment using the free GovernStack tool.
Step 1: Register your information assets
Everything in OCTAVE begins with the asset. An information asset is anything that holds, processes, or transmits data that has value to your organisation: customer databases, employee records, intellectual property, financial systems, email archives, source code repositories, paper files.
For each asset, document four things:
- Asset type — Is it an information asset (data), infrastructure (hardware/network), people (staff with critical knowledge), or software (applications)?
- Owner — Who is accountable for this asset? Not who uses it, but who decides how it should be protected. Typically a department head or senior manager.
- Classification — How sensitive is it? Public, Internal, Confidential, or Strictly Confidential. This directly affects the impact scoring later.
- Location — Where does it physically or logically reside? Cloud, on-premise server, SaaS application, filing cabinet?
Start with your most critical assets — the ones whose loss, disclosure, or corruption would cause the most harm. Most organisations find that 10–20 assets cover the vast majority of their information risk.
Step 2: Identify threats and vulnerabilities
For each asset, ask: what could go wrong? OCTAVE uses a structured threat library to ensure you consider the full range of scenarios, not just the ones that come to mind first. Common threat categories include:
- Unauthorised access — someone who should not have access gains it
- Data exfiltration — data is extracted from the organisation without authorisation
- Malware and ransomware — malicious software encrypts, destroys, or steals data
- Phishing and social engineering — staff are manipulated into revealing credentials or data
- Insider misuse — authorised users misuse their access intentionally
- Physical theft or loss — equipment containing data is stolen or lost
- System failure — hardware or software failure causes data loss or unavailability
- Supply chain compromise — a third-party vendor is breached, affecting your data
For each threat, also document the vulnerabilities that could be exploited — excessive user privileges, unpatched software, lack of encryption, inadequate physical security — and any controls already in place.
Step 3: Score risks using the CIA triad
This is where OCTAVE differs from simple risk matrices. Rather than a single "impact" score, each risk is assessed against three dimensions of the CIA triad:
- Confidentiality — What is the impact if this information is disclosed to unauthorised parties?
- Integrity — What is the impact if this information is modified, corrupted, or becomes unreliable?
- Availability — What is the impact if this asset becomes inaccessible?
Each dimension is scored 1 (low) to 3 (high). The overall impact value is the highest of the three CIA scores — the high watermark approach. This is then multiplied by a likelihood score (1–3: rare, possible, likely) to produce the composite risk score.
A 3×3 matrix categorises risks: scores of 1–2 are Low (green), 3–5 are Medium (amber), and 6–9 are High (red). High risks demand immediate action; medium risks require planned mitigation; low risks can be accepted and monitored.
Step 4: Build treatment plans
For every risk above your defined appetite threshold, select a treatment approach:
- Mitigate — implement controls to reduce likelihood or impact. Document the specific controls, the ISO 27001:2022 Annex A reference, the timeline for implementation, and who is responsible.
- Accept — acknowledge the risk and document the justification. Only appropriate for low and medium risks within your stated appetite.
- Transfer — shift the financial impact to a third party, typically through cyber insurance or contractual arrangements with a processor.
- Avoid — stop the activity that creates the risk. Sometimes the most pragmatic option for risks that cannot be adequately mitigated.
Each treatment plan should include a clear timeline and named individual responsible. "IT team will fix this" is not a treatment plan — "Head of IT will implement MFA on all admin accounts by 30 September 2026" is.
Exporting and using the output
A completed OCTAVE assessment produces two deliverables: a risk register (the spreadsheet of all identified risks with scores, treatments, and ownership) and a management report (a summary document showing the risk distribution, high-priority items, and treatment plan status).
The GovernStack tool exports both formats: download as a multi-sheet Excel spreadsheet for your working risk register, or generate a formatted PDF report for board and management presentations. Both are produced directly from your browser with no data leaving your machine.
How this fits into ISO 27001
ISO 27001:2022 clause 6.1.2 requires a documented information security risk assessment process. OCTAVE Allegro satisfies this requirement because it provides a repeatable, structured methodology that identifies risks to information assets, evaluates them against defined criteria, and produces a treatment plan mapped to Annex A controls. The output of the GovernStack tool — an asset register, scored risk register, and treatment plan — is directly usable as evidence in an ISO 27001 Stage 1 or Stage 2 audit.
For organisations also needing to quantify the financial impact of their top risks, the Data Breach Cost Calculator and GDPR Fine Estimator provide the figures needed for board-level reporting and cyber insurance applications.