Risk Register

24 risks tracked

24
Total
22
Mitigating
2
Accepted
Risks
RiskSeverityRisk ScoreStatusOwner
Appropriate contacts are not maintained resulting in delays in breach response and reporting.
medium
41mitigatingemal@avala.ai
Appropriate contacts with interest groups are not maintained resulting in a lack of understanding of current threats.
medium
41mitigatingemal@avala.ai
Assets are not identified and protected according to company requirements.
medium
41mitigatingemal@avala.ai
Background verification checks are not carried out on all candidates or are not proportional to the business requirements or the classification of the information to be accessed by the role resulting in increased risk of malicious insider threats.
medium
41mitigatingemal@avala.ai
Bad actor poses as CEO and demands transfer of funds.
high
63mitigatingemal@avala.ai
Company data is breached due to human error and/or misunderstanding of company requirements.
medium
41mitigatingemal@avala.ai
Company data is breached during a disaster due to control failures.
high
92mitigatingemal@avala.ai
Company data is breached, corrupted or made unavailable due to a malware attack.
high
31mitigatingemal@avala.ai
Company records are altered due to lack of proper access controls, segregation of duties, and/or supervision.
high
62mitigatingemal@avala.ai
Company systems and data are breached by a company vendor.
low
1mitigatingemal@avala.ai
Company systems and data are breached by unauthorized persons due to improper use of encryption.
medium
41mitigatingemal@avala.ai
Company systems and data are breached by unauthorized persons via a vulnerability in non-production systems or networks.
medium
4mitigatingemal@avala.ai
Company systems and data are breached in a non-production environment.
low
1acceptedemal@avala.ai
Company systems and data are breached or destroyed due to a natural disaster or malicious attack.
low
1acceptedemal@avala.ai
Consent for processing of PII is not captured and can't be demonstrated when needed.
medium
42mitigatingemal@avala.ai
Critical records are lost or destroyed leading to fines and/or loss of business.
critical
41mitigatingemal@avala.ai
Employees do not return equipment at termination resulting in a loss of resources and/or breach of company data.
medium
61mitigatingemal@avala.ai
Equipment failures result in unavailability of critical company data and systems.
medium
41mitigatingemal@avala.ai
Incident response is slow and ineffective.
high
91mitigatingemal@avala.ai
Insufficient customer contract language does not enable legal basis for international transfer of PII.
medium
41mitigatingemal@avala.ai
Personnel fraudulently alter information security records due to excessive pressures from management to perform on external audits.
high
32mitigatingemal@avala.ai
Personnel fraudulently establish or pay vendors due to lack of dual approval controls in the accounts payable process.
high
31mitigatingemal@avala.ai
Personnel have not received training on how to manage PII and/or respond to privacy requests.
medium
62mitigatingemal@avala.ai
Personnel mishandle data due to a misunderstanding of the company requirements.
critical
123mitigatingemal@avala.ai