Risk & Strategy / Risk Register Builder
§6.5What this is for: Build a PQC risk register with current algorithm, threat vector, likelihood, impact and mitigation.
What a good answer looks like: Every entry is scored (likelihood × impact) and carries a written mitigation. A risk with no mitigation is a note, and notes do not get treated.
Worked example: Add a risk entry for 'TLS Certificates (Public Web)' on RSA-2048 with Shor's Algorithm as the threat vector, Likelihood 4 — Likely and Impact 5 — Catastrophic: the card shows Score: 20 (Critical) and the Risk Summary counts it as Critical.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Read the four example entries, RSA-2048, AES-128, ECDSA P-256 and DH-2048, with their likelihood and impact: the Risk Summary is the shape of the register the programme will be held to, and every entry needs a named owner.
- GRC / Risk & Compliance
- Add Risk Entry for each asset with its threat, likelihood, impact, owner and mitigation strategy; the How Likelihood × Impact Scoring Works panel is the method to cite, and Copy Markdown or .pdf exports the register for the risk committee.
Risk Summary
Try it
Why does the tool say an unowned risk is a note, not a risk?
Next step
Next in Risk & Strategy: Risk Heatmap & Treatment PlanRisk Heatmap & Treatment Plan is the next Risk & Strategy tool in the Command Center.