|
3 | 3 | ## Purpose |
4 | 4 | The ASTRA Unified Working Spreadsheet simplifies real-time note-taking during threat modeling and security architecture reviews by capturing all observations, assumptions, risks, action items, follow-up questions, and administrative to-dos in one place. |
5 | 5 |
|
6 | | -## Spreadsheet Structure |
| 6 | +## Meeting Logistics Tab |
| 7 | +Captures logistical and attendee information separately: |
| 8 | +- Meeting ID |
| 9 | +- Date |
| 10 | +- Time |
| 11 | +- Attendee Names |
| 12 | +- Roles Represented |
| 13 | +- Meeting Format (Video, In-person, Hybrid) |
| 14 | +- Interviewer(s) |
| 15 | +- Additional Notes |
| 16 | + |
| 17 | +This tab provides critical context for each session, ensuring traceability and supporting proper documentation of participants and session conditions. |
| 18 | + |
| 19 | +## Major Groupings of the Main Tab |
| 20 | +The Main Tab organizes assessment information into three logical groups: |
7 | 21 |
|
8 | | -### Main Records Tab |
| 22 | +| Group | Columns | |
| 23 | +|:--|:--| |
| 24 | +| **General** | Record ID, Summary and Details | |
| 25 | +| **Risk** | Business Impact Area, Severity, Likelihood, Inherent Risk | |
| 26 | +| **Remediation** | Cost, Timeline, Difficulty, Impact (Mitigation Impact) | |
| 27 | +| **Resolve** | Residual Risk, Assigned Owner, Due Date, Status | |
| 28 | + |
| 29 | +This structure matches the natural assessment flow: understanding the risk, evaluating remediation options, and managing resolution. |
| 30 | + |
| 31 | +## Record Types |
9 | 32 |
|
10 | 33 | | Record ID Prefix | Record Type | |
11 | | -|:----------------|:------------| |
| 34 | +|:--|:--| |
12 | 35 | | O-xxx | Observation | |
13 | 36 | | A-xxx | Assumption | |
14 | 37 | | R-xxx | Risk Finding | |
15 | 38 | | AI-xxx | Critical Action Item | |
16 | 39 | | TD-xxx | Administrative To-Do | |
17 | 40 | | FU-xxx | Follow-up Question | |
18 | 41 |
|
19 | | -### Columns in the Main Records Tab |
20 | | - |
21 | | -- **Record ID**: Unique identifier for each entry based on record type prefix. |
22 | | -- **Summary and Details**: Enter all relevant notes, details, context, or clarifications in this single narrative field. |
23 | | -- **Category**: Select from InfoSec, Privacy, Operational, or Other. |
24 | | -- **Severity**: Critical, High, Medium, Low, or N/A (primarily for Risk Findings). |
25 | | -- **Likelihood**: High, Medium, Low, or N/A (primarily for Risk Findings). |
26 | | -- **To Repair: Cost**: High, Medium, Low, or N/A. |
27 | | -- **To Repair: Timeline**: Enter estimated time required or mark N/A. |
28 | | -- **To Repair: Difficulty**: High, Moderate, Low, or N/A. |
29 | | -- **Residual Risk**: High, Medium, Low, or N/A. |
30 | | -- **Assigned Owner**: Specify the responsible person or role. |
31 | | -- **Due Date**: Target completion date. |
32 | | -- **Status**: |
33 | | - - **Confirm**: Needs immediate follow-up or verification (especially for Observations, Assumptions, and Follow-up Questions). |
34 | | - - **Open**: Item identified and actively tracked. |
35 | | - - **In Progress**: Work or clarification actively underway. |
36 | | - - **Closed**: Completed or resolved. |
37 | | - - **Deferred**: Postponed intentionally. |
38 | | - - **Promoted to Risk**: Follow-up or Action escalated to a formal Risk Finding. |
39 | | - |
40 | | -### Meeting Demographics Tab |
| 42 | +## Field Option Definitions |
41 | 43 |
|
42 | | -Captures logistical and attendee information separately: |
43 | | -- Meeting ID |
44 | | -- Date |
45 | | -- Time |
46 | | -- Attendee Names |
47 | | -- Roles Represented |
48 | | -- Meeting Format (Video, In-person, Hybrid) |
49 | | -- Interviewer(s) |
50 | | -- Additional Notes |
| 44 | +### Business Impact Area (BIA) |
| 45 | +**Purpose:** Classify the primary business consequence if the identified risk materializes. |
| 46 | + |
| 47 | +**Options:** |
| 48 | +- **Financial** — Direct monetary loss (e.g., theft, fines, lost revenue). |
| 49 | +- **Reputational** — Damage to brand, customer trust, or public image. |
| 50 | +- **Operational** — Disruption of internal systems, services, or business operations. |
| 51 | +- **Safety** — Harm to physical health, life, or environment. |
| 52 | +- **Regulatory** — Violation of laws, standards, or contractual obligations. |
| 53 | +- **Privacy** — Unauthorized access or misuse of personal or sensitive data. |
| 54 | +- **Other** — Impact not covered above (describe in Notes). |
| 55 | + |
| 56 | +**Note:** Security/InfoSec is intentionally not a BIA category because it represents a cause or vector, not a direct business impact. Business owners experience security failures through tangible consequences like financial loss, operational disruption, or regulatory violations. |
| 57 | + |
| 58 | +### Severity |
| 59 | +**Purpose:** Rate the potential seriousness of the impact if the risk materializes. |
| 60 | + |
| 61 | +**Options:** |
| 62 | +- **High** — Severe impact on business operations, finances, reputation, safety, or compliance. |
| 63 | +- **Medium** — Moderate disruption, recoverable without major long-term effects. |
| 64 | +- **Low** — Minor inconvenience or negligible business impact. |
| 65 | + |
| 66 | +### Likelihood |
| 67 | +**Purpose:** Estimate how likely the risk is to occur. |
| 68 | + |
| 69 | +**Options:** |
| 70 | +- **High** — Likely to happen within the expected operational lifecycle. |
| 71 | +- **Medium** — Possible but not guaranteed; moderate chance. |
| 72 | +- **Low** — Unlikely under normal conditions; rare event. |
| 73 | + |
| 74 | +### Inherent Risk |
| 75 | +**Purpose:** Combined pre-mitigation risk level, derived from Severity and Likelihood. |
| 76 | + |
| 77 | +**Options:** |
| 78 | +- **Critical** — High Severity + High Likelihood. |
| 79 | +- **High** — High impact or high probability individually. |
| 80 | +- **Medium** — Moderate impact and probability. |
| 81 | +- **Low** — Low impact and/or low probability. |
| 82 | +- **Informational** — Not a direct risk, but noteworthy. |
| 83 | + |
| 84 | +(Determined using the Risk Matrix.) |
| 85 | + |
| 86 | +### Cost (Remediation Group) |
| 87 | +**Purpose:** Estimate the effort or resources required to fix the identified issue. |
| 88 | + |
| 89 | +**Options:** |
| 90 | +- **High** — Significant expense, new project, major investment. |
| 91 | +- **Medium** — Manageable cost, requires planning and allocation. |
| 92 | +- **Low** — Minimal cost, can be handled within existing budgets. |
| 93 | + |
| 94 | +### Timeline (Remediation Group) |
| 95 | +**Purpose:** Estimate the time needed to complete mitigation. |
| 96 | + |
| 97 | +**Options:** |
| 98 | +- **High** — More than 6 months. |
| 99 | +- **Medium** — 1-6 months. |
| 100 | +- **Low** — Less than 1 month. |
| 101 | +- *(Or specify explicit duration if needed.)* |
| 102 | + |
| 103 | +### Difficulty (Remediation Group) |
| 104 | +**Purpose:** Assess the technical and organizational challenge level to fix the issue. |
| 105 | + |
| 106 | +**Options:** |
| 107 | +- **High** — Significant technical complexity, cross-team or leadership involvement required. |
| 108 | +- **Medium** — Moderate technical challenge, local to project or platform team. |
| 109 | +- **Low** — Straightforward fix, minimal friction expected. |
| 110 | + |
| 111 | +### Impact (Remediation Group) |
| 112 | +**Purpose:** Measure how much the proposed mitigation is expected to reduce risk. |
| 113 | + |
| 114 | +**Options:** |
| 115 | +- **High** — Fix will almost fully eliminate the risk. |
| 116 | +- **Medium** — Fix will reduce but not eliminate the risk. |
| 117 | +- **Low** — Fix will only slightly mitigate the risk. |
| 118 | + |
| 119 | +### Residual Risk |
| 120 | +**Purpose:** Estimate the risk level that will remain after the mitigation is applied. |
| 121 | + |
| 122 | +**Options:** |
| 123 | +- **High** — Substantial risk remains even after mitigation. |
| 124 | +- **Medium** — Some manageable risk remains. |
| 125 | +- **Low** — Minimal risk remains after mitigation. |
| 126 | +- **Informational** — Mitigation effectively eliminates operational risk, leaving informational observations. |
| 127 | + |
| 128 | +### Status |
| 129 | +**Purpose:** Track the current state of the finding, action item, or assumption. |
| 130 | + |
| 131 | +**Options:** |
| 132 | +- **Confirm** — Needs immediate follow-up or verification. |
| 133 | +- **Open** — Newly identified and active. |
| 134 | +- **In Progress** — Work underway to address. |
| 135 | +- **Closed** — Fully resolved and verified. |
| 136 | +- **Deferred** — Deliberately postponed. |
| 137 | +- **Promoted to Risk** — Critical action item or follow-up converted into a formal risk finding. |
51 | 138 |
|
52 | 139 | ## How to Use |
53 | | -- Use the Main Records Tab during interviews to log observations, assumptions, risks, action items, follow-up questions, and administrative to-dos immediately. |
54 | | -- Update statuses and assigned owners actively during and after the session. |
55 | | -- Use the Meeting Demographics Tab to record participant and logistical details at the beginning of each interview. |
56 | | -- Review and finalize statuses post-interview to ensure traceability and closure. |
| 140 | +- Use the Main Tab during interviews to log observations, assumptions, risks, action items, follow-up questions, and administrative to-dos immediately. |
| 141 | +- Use Business Impact Area, Severity, Likelihood, and Inherent Risk columns to quickly assess potential issues. |
| 142 | +- Capture Remediation-related information (Cost, Timeline, Difficulty, Impact) when mitigation options are discussed. |
| 143 | +- Assign owners, due dates, and statuses for tracking follow-up and closure. |
| 144 | +- Record meeting and participant details separately in the Meeting Logistics Tab. |
| 145 | +- Review and finalize statuses post-interview to ensure traceability and completion. |
57 | 146 |
|
58 | | -**Note**: Keep entries clear, concise, and comprehensive for efficient follow-up and final reporting. |
| 147 | +**Note**: Entries should remain clear, concise, and comprehensive to support smooth report generation. |
59 | 148 |
|
0 commit comments