Skip to main content

governanceVersion 1SOC2ISO27001NIST800-171

Risk Management Policy

Qualitative risk methodology aligned with ISO 27005 and NIST SP 800-30.

Download PDFSHA-256 1fdafb5271969847…

Risk Management Policy

1. Purpose

Establishes how Rex Black identifies, analyzes, treats, and monitors risks to the confidentiality, integrity, and availability of its information assets and its business obligations.

2. Approach

Rex Black operates a qualitative risk management program aligned with ISO 27005 and NIST SP 800-30, suitable for a small company. Quantitative techniques (ALE / SLE) are applied where useful for specific decisions.

3. Risk register

  1. A single Risk Register is maintained at registers/risk-register.md.
  2. Each entry has: ID, date opened, risk description, asset, threat, vulnerability, inherent likelihood, inherent impact, inherent score, owner, planned treatment, residual score, review date, and status.
  3. The Register is reviewed:
    • Monthly during leadership stand-up for movers.
    • Quarterly in depth by the Security Officer and CEO.
    • Annually end-to-end during ISMS management review.

4. Scales

4.1 Likelihood

Level Label Expected frequency
1 Rare < once every 5y
2 Unlikely once in 2–5y
3 Possible once in 1–2y
4 Likely once in 6–12 mo
5 Almost certain more than annually

4.2 Impact

Level Confidentiality Integrity Availability Financial
1 No disclosure No distortion < 1 hr outage < $1k
2 Internal only Minor, recoverable 1–8 hr outage < $10k
3 Confidential disclosed Material, recoverable 8 hr – 2 day outage < $100k
4 Restricted partial Widespread distortion 2–7 day outage < $1M
5 Restricted wholesale Unrecoverable > 7 day outage > $1M

Risk score = Likelihood × Impact (1–25).

4.3 Tolerance

  • Low (1–5): accept and monitor.
  • Medium (6–12): treat within 12 months.
  • High (13–20): treat within 90 days.
  • Critical (≥ 21): treat within 30 days; CEO notified.

5. Treatment options

  1. Mitigate: implement controls.
  2. Transfer: insurance or contractual shift (e.g., DPA indemnities, cyber policy).
  3. Avoid: stop the activity that creates the risk.
  4. Accept: formally, with CEO sign-off for Medium or higher.

6. Insurance

Rex Black maintains a cyber liability policy with $5M aggregate coverage. Policy documents are stored in the Vault; the coverage summary is referenced in the Risk Register where used for risk transfer.

7. Inputs to the register

  • Findings from audits, penetration tests, and tabletop exercises.
  • Incidents and near-misses.
  • Vendor risk assessments.
  • New regulations or contractual obligations.
  • Threat intelligence (CISA KEV, vendor advisories).

8. Roles & responsibilities

Role Responsibility
Security Officer Owns the Register; facilitates reviews.
Risk owner Named for each risk; drives treatment to completion.
CEO Approves treatment plans; signs off on acceptances.

9. References

  • registers/risk-register.md
  • 012-incident-response-plan.md
  • 017-vendor-subprocessor-management-policy.md

10. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center