OCTAVE Risk Assessment Tool — Free Interactive Template
The OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) methodology is one of the most widely recognised frameworks for information security risk assessment. Developed by Carnegie Mellon University, OCTAVE Allegro provides a streamlined, asset-focused approach that is practical for organisations of any size. This free interactive tool walks you through the complete OCTAVE Allegro process in four steps: register your information assets, identify threats and vulnerabilities against each, score risks using the CIA triad (Confidentiality, Integrity, Availability) with a 3×3 likelihood-impact matrix, and build a treatment plan with ISO 27001:2022 Annex A control references. Your progress is saved in your browser — no data is ever sent to a server. The output is a complete risk register that can be printed or exported as PDF directly from the browser.
Assets
Register information assets
Based on OCTAVE Allegro methodology with ISO/IEC 27001:2022 Annex A control mapping. CIA triad scoring with 3×3 risk matrix. All data is stored in your browser only — nothing is sent to any server. Use Ctrl/Cmd+P to export as PDF.
How this OCTAVE risk assessment works
This tool implements a simplified version of the OCTAVE Allegro methodology — a structured, asset-focused approach to information security risk assessment developed by Carnegie Mellon University's Software Engineering Institute. It walks you through four steps that mirror the core OCTAVE process: identifying your critical information assets, mapping the threats and vulnerabilities relevant to each, scoring risks using the CIA triad (Confidentiality, Integrity, Availability) with a 3×3 likelihood-impact matrix, and creating a treatment plan with references to ISO 27001:2022 Annex A controls.
CIA triad scoring explained
Every risk is assessed against three dimensions. Confidentiality measures the impact if the information is disclosed to unauthorised parties — from public information (score 1) to highly sensitive data whose disclosure would cause severe harm (score 3). Integrity measures the impact if the information is modified, corrupted, or becomes unreliable — from minimal business impact (1) to unacceptable consequences (3). Availability measures the impact if the asset becomes inaccessible — from tolerance of up to 7 days downtime (1) to systems required 24/7 where any outage is critical (3).
The overall impact value is the maximum of the three CIA scores, reflecting the principle that a risk is as severe as its worst-case dimension. This is then multiplied by the likelihood score (1–3) to produce the composite risk value.
Using the output for ISO 27001
ISO 27001:2022 clause 6.1.2 requires organisations to define and apply an information security risk assessment process. The output of this tool — a structured risk register with asset identification, threat analysis, CIA impact scoring, risk evaluation, and treatment plans referencing Annex A controls — directly satisfies several requirements of this clause. Print or export the completed assessment as PDF using your browser's print function (Ctrl/Cmd+P) and retain it as part of your ISMS documentation.
For a complementary risk visualisation tool, see the 5×5 Risk Matrix Generator which produces a colour-coded matrix suitable for management presentations and board reporting.