Security Risk Management Policy
Purpose
This policy sets out how Hybrowlabs identifies, assesses, treats, tracks, and reviews security risks, so that the same method is applied consistently across the business.
Scope
The policy covers risks to our applications, infrastructure, and data, as well as risks arising from vendors, personnel, operational processes, legal and compliance obligations, and the commitments we make to customers.
Risk identification
Risks come to light from many directions: architecture reviews, vulnerability assessments, incidents, audits, customer security reviews, change reviews, vendor assessments, cloud and security advisories, and day-to-day observations by our own teams.
Control owners record a risk whenever there is a plausible impact to confidentiality, integrity, availability, privacy, compliance, or continuity of service.
Risk rating method
Each risk is rated on two dimensions — how likely it is to occur, and how much damage it would do. The assessment of impact takes account of:
- Sensitivity of the data involved
- Number of users or customers affected
- How easily the weakness could be exploited
- Disruption to the business
- Regulatory exposure
- Contractual consequences
- Reputational harm
The combined rating is recorded as Critical, High, Medium, Low, or Informational, and it determines how quickly the risk is dealt with and who needs to approve the outcome.
Treatment options
Every recorded risk is assigned one of four treatments:
- Mitigate — put controls in place to reduce the likelihood or the impact.
- Avoid — stop the activity or change the design so the risk no longer arises.
- Transfer — shift the exposure through contractual, insurance, or vendor arrangements where that is appropriate.
- Accept — take the risk knowingly, with the rationale, approver, owner, and review date recorded.
Risk register: Helpdesk tickets
Each entry in the risk register records:
- Description of the risk
- Affected asset or process
- Owner
- Rating
- Due date
- Status
- Supporting evidence
- Review date
Critical and high risks stay under active review until they are closed. The full register is reviewed periodically and again after any major incident, significant architecture change, or customer-impacting deployment.
Evidence maintained
- Risk Tickets
- Review meeting notes
- Treatment tickets
- Exception approvals
- Closure evidence
- Residual-risk acceptance ticket records