Scenario library
The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.
Risk5 Sept 20263 min read
On this page
scenario-library.xlsx · 11 kBLicensed CC BY 4.0
What this is
The set of risk scenarios an organisation assesses each cycle, kept alive rather than rebuilt before each audit. One sheet holds the risk sources and what the deliberate ones want, one the scenarios, scored and owned, and one the events that pull a review forward. It is deliberately not a register: it carries no acceptance decision, only a register ID pointing at the row that does.
How to use it
- Say which approach this cycle used, on the Read first sheet. Identification starts from risk sources and events, or from assets and weaknesses; both can describe the same scenario 1. See 3.2.
- Fill Sources before Scenarios. Risk sources are human, environmental or technical, and a human source may act without intent 2. Attackers alone answer no all-hazards question.
- Write a desired end state only for deliberate sources — the situation that source wants to reach, which is how the informative annex expresses motivation 3. Otherwise write not applicable, and why.
- Write fifteen to forty scenarios, each naming a source, an event, the activities affected, the assets, the consequence type and the objective. See 3.4.
- Name an owner on every row while the scenario is still being written; the owner holds both the accountability and the authority 4.
- Score consequence, then likelihood, then read the level. All three use the scales in
risk-criteria-and-appetite.xlsx; the level comes off its Matrix sheet. It is the level with existing controls in place: the register's residual level. See 3.5 to 3.7. - Fill the basis column with a dated record, sector report or test result.
- Set the treatment option, then hand the row to the register. The four closed values are the option names printed at clause 8.2: risk avoidance, risk modification, risk retention and risk sharing 5.
- Keep the Events log current. Retained scenarios become monitoring scenarios, built from the factors that show one starting 6. See 3.10.
Delete the nine example rows first. Each is invented and prefixed EXAMPLE - delete.
What good looks like
Six of the eighteen Scenarios columns, from one example.
| Scenario ID | Event | Consequence | Likelihood | Level | Register ID |
|---|---|---|---|---|---|
| SCN-002 | An engineer changes a production access rule without review, and a control recorded as implemented stops running | 3. Moderate | 4. Likely | High | R-007 |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Event | yes | What happens, in one testable sentence | A missing control written as an event |
| Consequence type | yes | One of the six criteria dimensions, numbered | Two dimensions in one cell, so nothing sets the level |
| Basis for the likelihood | yes | The dated record, report or test behind the band | Left blank, turning the band into a show of hands |
| Level | yes | Read off the criteria workbook's Matrix sheet | Derived by multiplying consequence by likelihood |
| Treatment option | yes when outside appetite | One of the four names printed at clause 8.2 | A fifth value invented to avoid choosing |
| Register ID | yes when treated | The register row holding the decision, approver and date | An acceptance recorded here instead of in the register |
Download
- File:
scenario-library.xlsx(xlsx, 11 KB) — four sheets: Read first, Sources, Scenarios, Events log. - Markdown variant:
content/templates/assets/_scenario-library.md, same tables. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.
Related
- Playbook: Scenario-based risk assessment
- Template: Risk criteria and appetite statement, whose scales this reuses
- Template: Risk register, which holds the decisions
References
- ISO/IEC. Guidance on managing information security risks. ISO/IEC 27005:2022, licensed copy 7
- ISO/IEC. Information security management systems. ISO/IEC 27001:2022 8
Annex A of ISO/IEC 27005:2022 is informative. Scenario counts and review rhythms are organisational choices, not requirements of either standard.
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication, not affiliated with, authorized, sponsored or endorsed by ISO, IEC or any other standards body.
Sources
- 1ISO/IEC 27005:2022 clause 7.2.1, licensed copy · verified 2026-09-05
- 2ISO/IEC 27005:2022 clause 3.1.6, licensed copy · verified 2026-09-05
- 3ISO/IEC 27005:2022 clause A.2.3, licensed copy · verified 2026-09-05
- 4ISO/IEC 27005:2022 clause 7.2.2, licensed copy · verified 2026-09-05
- 5ISO/IEC 27005:2022 clause 8.2, licensed copy · verified 2026-09-05
- 6ISO/IEC 27005:2022 clauses 10.5.1 and A.2.7, licensed copy · verified 2026-09-05
- 7ISO/IEC 27005:2022 clauses 3.1.6, 7.2.1, 7.2.2, 8.2, A.2.3 and A.2.7, licensed copy · verified 2026-09-05
- 8ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03