governanceVersion 1SOC2ISO27001NIST800-171
Risk Management Policy
Qualitative risk methodology aligned with ISO 27005 and NIST SP 800-30.
Risk Management Policy
1. Purpose
Establishes how Rex Black identifies, analyzes, treats, and monitors risks to the confidentiality, integrity, and availability of its information assets and its business obligations.
2. Approach
Rex Black operates a qualitative risk management program aligned with ISO 27005 and NIST SP 800-30, suitable for a small company. Quantitative techniques (ALE / SLE) are applied where useful for specific decisions.
3. Risk register
- A single Risk Register is maintained at
registers/risk-register.md. - Each entry has: ID, date opened, risk description, asset, threat, vulnerability, inherent likelihood, inherent impact, inherent score, owner, planned treatment, residual score, review date, and status.
- The Register is reviewed:
- Monthly during leadership stand-up for movers.
- Quarterly in depth by the Security Officer and CEO.
- Annually end-to-end during ISMS management review.
4. Scales
4.1 Likelihood
| Level | Label | Expected frequency |
|---|---|---|
| 1 | Rare | < once every 5y |
| 2 | Unlikely | once in 2–5y |
| 3 | Possible | once in 1–2y |
| 4 | Likely | once in 6–12 mo |
| 5 | Almost certain | more than annually |
4.2 Impact
| Level | Confidentiality | Integrity | Availability | Financial |
|---|---|---|---|---|
| 1 | No disclosure | No distortion | < 1 hr outage | < $1k |
| 2 | Internal only | Minor, recoverable | 1–8 hr outage | < $10k |
| 3 | Confidential disclosed | Material, recoverable | 8 hr – 2 day outage | < $100k |
| 4 | Restricted partial | Widespread distortion | 2–7 day outage | < $1M |
| 5 | Restricted wholesale | Unrecoverable | > 7 day outage | > $1M |
Risk score = Likelihood × Impact (1–25).
4.3 Tolerance
- Low (1–5): accept and monitor.
- Medium (6–12): treat within 12 months.
- High (13–20): treat within 90 days.
- Critical (≥ 21): treat within 30 days; CEO notified.
5. Treatment options
- Mitigate: implement controls.
- Transfer: insurance or contractual shift (e.g., DPA indemnities, cyber policy).
- Avoid: stop the activity that creates the risk.
- Accept: formally, with CEO sign-off for Medium or higher.
6. Insurance
Rex Black maintains a cyber liability policy with $5M aggregate coverage. Policy documents are stored in the Vault; the coverage summary is referenced in the Risk Register where used for risk transfer.
7. Inputs to the register
- Findings from audits, penetration tests, and tabletop exercises.
- Incidents and near-misses.
- Vendor risk assessments.
- New regulations or contractual obligations.
- Threat intelligence (CISA KEV, vendor advisories).
8. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Owns the Register; facilitates reviews. |
| Risk owner | Named for each risk; drives treatment to completion. |
| CEO | Approves treatment plans; signs off on acceptances. |
9. References
registers/risk-register.md012-incident-response-plan.md017-vendor-subprocessor-management-policy.md
10. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.