Risk assessment tool

Build a documented risk assessment in your browser. Nothing you enter is sent to us.

Several standards expect a documented, periodic risk assessment: HIPAA calls it a risk analysis, ISO 27001 puts it in clause 6.1.2, SOC 2 covers it under CC3, and PCI DSS 4.x asks for targeted risk analyses. Most first-timers try to do it in a spreadsheet and get stuck, because the work is relational. The same risk applies to many assets, threats apply to many systems, and scores have to stay consistent across all of it.

This tool walks you through it in seven steps, with a starting catalog of threats, weaknesses, and common scenarios so you are not staring at an empty grid. At the end you get a risk register, a treatment plan, a heat map, a methodology statement, and a sign-off page: the parts an auditor looks for.

Your data stays in your browser

Everything you type is stored locally on your device and nowhere else. It is never sent to Infosec Standards, to Aeris Secure, or to any third party. There is no account and no upload.

We do count anonymous usage (how many people start an assessment, which step they reach, how many export) with Google Analytics, the same as the rest of the site. Those counts never include anything you type. See the privacy notice for the detail.

Because the only copy is in this browser, the export is your save button. Download the JSON file when you finish a session. It re-opens here later, on any computer, and next year you can start from it instead of beginning again.

How it works

  1. Scope. What the assessment covers, who is doing it, and why.
  2. Scales. What a 1 and a 5 mean for likelihood and impact, and where your threshold sits.
  3. Assets. The systems, data, people, places, and vendors that matter. Group similar things.
  4. Threats. Who or what could cause harm, what could happen, and the weaknesses that allow it.
  5. Scenarios and scores. Realistic combinations, scored for likelihood and impact against the controls you have today.
  6. Treatment. For each risk above your threshold: reduce it, live with it, transfer it, or avoid it.
  7. Review and export. Register, heat map, sign-off, and your files to keep.

The structure and vocabulary follow NIST SP 800-30 Rev. 1, simplified for a first assessment. The methodology page documents the scales, the matrix, and where we depart from the publication, so you can hand it to an assessor.

What this is not

It is not a vulnerability scan and not a review of whether your controls actually work. Those are a vulnerability assessment and a security assessment. It is also not a shared system: one person at a time, one browser at a time.