GovernStack
🛡️Cybersecurity

OCTAVE Risk Assessment Tool — Free Interactive Template

The OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) methodology is one of the most widely recognised frameworks for information security risk assessment. Developed by Carnegie Mellon University, OCTAVE Allegro provides a streamlined, asset-focused approach that is practical for organisations of any size. This free interactive tool walks you through the complete OCTAVE Allegro process in four steps: register your information assets, identify threats and vulnerabilities against each, score risks using the CIA triad (Confidentiality, Integrity, Availability) with a 3×3 likelihood-impact matrix, and build a treatment plan with ISO 27001:2022 Annex A control references. Your progress is saved in your browser — no data is ever sent to a server. The output is a complete risk register that can be printed or exported as PDF directly from the browser.

Assets

Register information assets

Add your first information asset to begin the risk assessment

Based on OCTAVE Allegro methodology with ISO/IEC 27001:2022 Annex A control mapping. CIA triad scoring with 3×3 risk matrix. All data is stored in your browser only — nothing is sent to any server. Use Ctrl/Cmd+P to export as PDF.

How this OCTAVE risk assessment works

This tool implements a simplified version of the OCTAVE Allegro methodology — a structured, asset-focused approach to information security risk assessment developed by Carnegie Mellon University's Software Engineering Institute. It walks you through four steps that mirror the core OCTAVE process: identifying your critical information assets, mapping the threats and vulnerabilities relevant to each, scoring risks using the CIA triad (Confidentiality, Integrity, Availability) with a 3×3 likelihood-impact matrix, and creating a treatment plan with references to ISO 27001:2022 Annex A controls.

CIA triad scoring explained

Every risk is assessed against three dimensions. Confidentiality measures the impact if the information is disclosed to unauthorised parties — from public information (score 1) to highly sensitive data whose disclosure would cause severe harm (score 3). Integrity measures the impact if the information is modified, corrupted, or becomes unreliable — from minimal business impact (1) to unacceptable consequences (3). Availability measures the impact if the asset becomes inaccessible — from tolerance of up to 7 days downtime (1) to systems required 24/7 where any outage is critical (3).

The overall impact value is the maximum of the three CIA scores, reflecting the principle that a risk is as severe as its worst-case dimension. This is then multiplied by the likelihood score (1–3) to produce the composite risk value.

Using the output for ISO 27001

ISO 27001:2022 clause 6.1.2 requires organisations to define and apply an information security risk assessment process. The output of this tool — a structured risk register with asset identification, threat analysis, CIA impact scoring, risk evaluation, and treatment plans referencing Annex A controls — directly satisfies several requirements of this clause. Print or export the completed assessment as PDF using your browser's print function (Ctrl/Cmd+P) and retain it as part of your ISMS documentation.

For a complementary risk visualisation tool, see the 5×5 Risk Matrix Generator which produces a colour-coded matrix suitable for management presentations and board reporting.

Frequently Asked Questions

What is OCTAVE Allegro?

OCTAVE Allegro is a streamlined version of the OCTAVE methodology developed by Carnegie Mellon University. It focuses on information assets rather than infrastructure, making it more accessible for organisations that want to conduct risk assessments without extensive workshop facilitation. It is widely used for ISO 27001 compliance, SOC 2 readiness, and general information security risk management.

How does this tool differ from the 5×5 Risk Matrix Generator?

The 5×5 Risk Matrix Generator on GovernStack is a general-purpose risk visualisation tool suitable for any type of risk (project, operational, strategic). This OCTAVE tool is specifically designed for information security risk assessment — it uses CIA triad impact scoring (Confidentiality, Integrity, Availability), maps threats to assets, references ISO 27001:2022 Annex A controls, and produces a structured risk register with treatment plans.

Is my data stored on a server?

No. All data entered into this tool is stored exclusively in your browser using localStorage. Nothing is transmitted to any server. You can clear all data at any time using the Reset button. To export your risk register, use the Print/PDF button or Ctrl+P to save as PDF.

What is CIA triad scoring?

The CIA triad (Confidentiality, Integrity, Availability) is the foundational model for information security. Each risk is scored against all three dimensions: how would a breach of confidentiality affect the asset? What about loss of data integrity? And what is the impact of the asset being unavailable? The highest of the three scores becomes the overall impact value, which is multiplied by likelihood to produce the risk score.

Can I use this for ISO 27001 certification?

This tool produces output that is consistent with ISO 27001:2022 requirements for risk assessment — including asset identification, threat and vulnerability analysis, likelihood and impact scoring, risk evaluation, and treatment planning with Annex A control references. However, your certification auditor will want to see that the risk assessment is integrated into your broader ISMS (Information Security Management System) and reviewed regularly. The tool is a strong starting point, but it should be supplemented with organisational context, management review minutes, and evidence of implementation.

How often should a risk assessment be reviewed?

ISO 27001 requires risk assessments to be reviewed at planned intervals and whenever significant changes occur. In practice, most organisations conduct a full review annually and update the register when new assets are deployed, significant incidents occur, or the threat landscape changes materially. The localStorage persistence in this tool allows you to return to your assessment over time.

Related Tools