Skip to main content

Compliance and Risk Matrices

This page maps the Statement of Applicabilities, the organization risks and legal obligations directly to their mitigating ISO 27001 controls and in case of NIS 2 SC-30 the other mitigation policies and processes. It provides auditors and stakeholders with a single, transparent view of how the organization maintains compliance and addresses security threats simultaneously.

Risk ID Risk NamePriority Reviewed
Data breachesL2026-06-22
Compliance issues - OperationsM2026-08-01
Compliance issues -BusinessM2025-12-23
Reputation damage - OperationsL2025-12-23
Reputation damage - BusinessL2025-12-23
Financial lossesL2025-12-23
Outdated policiesL2025-12-23
Outdated policiesL2025-12-23
Non-complianceL2025-12-23
Non-complianceL2025-12-23
Increased risk of data breachesL2025-12-23
Increased risk of data breachesL2025-12-23
Decreased employee awarenessL2025-12-23
Decreased employee engagementL2025-12-23
Processes incorrect or not executedL2025-12-23
Non authorized people or processes gain access via devices used for work.L2025-12-23
Devices for work used in uncontrolled/unknown work environments - mishandlingL2025-12-23
Devices for work used in uncontrolled/unknown work environments - configurationL2025-12-23
Employees with a history that conflicts with information security profile neededL2025-12-23
Employees not sufficiently aware of their duties - Business & GeneralL2026-06-24
Employees not sufficiently aware of their duties - OperationsL2025-12-23
Employees not sufficiently aware of their duties - ManagementM2026-08-01
Employees not willing to complyL2025-12-23
Employees leaving the organization have access to the organization's assets or information.L2025-12-23
Incorrect handling of security incidentsL2025-12-23
Supplier works in a not sufficient compliant wayL2025-12-23
Supplier delivers results that are not sufficiently compliant or does not deliver in accordance to the contractL2025-12-23
Insufficient priority, attention, or means to ensure the required level of the ISMSL2026-08-01
Unauthorized access - OperationsL2025-12-23
Unauthorized access - BusinessL2025-12-23
Insider threat - OperationsL2025-12-23
Insider threat - BusinessL2025-12-23
Lack of accountability - OperationsL2025-12-23
Lack of accountability - BusinessL2025-12-23
Technical vulnerabilitiesL2025-12-23
Key managementM2025-12-23
Implementation vulnerabilitiesL2025-12-23
Algorithmic vulnerabilitiesL2025-12-23
Legal and regulatory complianceL2025-12-23
Lack of security testingL2025-12-23
Vulnerabilities in new systemsL2025-12-23
Unauthorized changes - OperationsL2025-12-23
Unauthorized changes - BusinessL2025-12-23
Lack of visibilityL2025-12-23
Lack of accountability for assetsL2025-12-23
Inconsistent classificationL2026-08-01
Operational disruptionL2025-12-23
Loss of informationL2025-12-23
Delayed incident responseL2025-12-23
Unsecure networkL2025-12-23
Unsafe transport of information and unsafe access to information in application services via networkL2025-12-23
Insecure development of (unsafe) softwareL2025-12-23
Insufficient continuity Security OfficerL2026-08-01
Insufficient measures against malicious softwareL2025-12-23
Adding incorrect user during Workspace creationL2025-12-23
Lack of automation leading to human errorsL2025-12-23
Authorized users are unable to execute the necessary actionL2025-12-23
Downtime Entra IDL2025-12-23
Data center destructionL2026-02-23
RedundancyH2026-08-18
Platform or VM unavailabilityL2025-12-23
Application changesL2025-12-23
Incorrect or incomplete reportingL2025-12-23
Secret ManagementL2025-12-23
Control IDControl Name
Policies for information security
Information security roles and responsibilities
Segregation of duties
Management responsibilities
Contact with authorities
Contact with special interest groups
Threat intelligence
Information security in project management
Inventory of information and other associated assets
Acceptable use of information and other associated assets
Return of assets
Classification of information
Labelling of information
Information transfer
Access control
Identity management
Authentication information
Access rights
Information security in supplier relationships
Addressing information security within supplier agreements
Managing information security in the information and communication technology (ICT) supply chain
Monitoring, review and change management of supplier services
Information security for use of cloud services
Information security incident management planning and preparation
Assessment and decision on information security events
Response to information security incidents
Learning from information security incidents
Collection of evidence
Information security during disruption
ICT readiness for business continuity
Legal, statutory, regulatory and contractual requirements
Intellectual property rights
Protection of records
Privacy and protection of personal identifiable information (PII)
Independent review of information security
Compliance with policies, rules and standards for information security
Documented operating procedures
Screening
Terms and conditions of employment
Information security awareness, education and training
Disciplinary process
Responsibilities after termination or change of employment
Confidentiality or non-disclosure agreements
Remote working
Information security event reporting
Physical security perimeters
Physical entry
Securing offices, rooms and facilities
Physical security monitoring
Protecting against physical and environmental threats
Working in secure areas
Clear desk and clear screen
Equipment siting and protection
Security of assets off-premises
Storage media
Supporting utilities
Cabling security
Equipment maintenance
Secure disposal or re-use of equipment
User end point devices
Privileged access rights
Information access restriction
Access to source code
Secure authentication
Capacity management
Protection against malware
Management of technical vulnerabilities
Configuration management
Information deletion
Data masking
Data leakage prevention
Information backup
Redundancy of information processing facilities
Logging
Monitoring activities
Clock synchronization
Use of privileged utility programs
Installation of software on operational systems
Networks security
Security of network services
Segregation of networks
Web filtering
Use of cryptography
Secure development life cycle
Application security requirements
Secure system architecture and engineering principles
Secure coding
Security testing in development and acceptance
Outsourced development
Separation of development, test and production environments
Change management
Test information
Protection of information systems during audit testing

Risk-Control Source - RiskControl.json