IT Security Risk Assessment Methodology

SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999) Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually Aligned to: ISO/IEC 27005, NIST Cybersecurity Framework 2.0

1. Purpose

Defines the repeatable method used to assess information security risk, feeding the Risk Management Policy & Register (A4).

2. The eight-step method

Step 1 — Establish scope and context. Define what is being assessed (the whole platform at annual review; a specific change or supplier at trigger-based review), the customers and data types in scope, applicable obligations (Australian Privacy Act and APPs, the NDB scheme, GDPR/UK where a customer's data attracts it), and the risk appetite: near-zero appetite for cross-tenant data exposure, low appetite for availability loss, moderate appetite for feature-level defects.

Step 2 — Asset inventory. Identify the assets in scope and their owner and sensitivity. Primary assets: customer client documents; extracted transaction and ledger data; Xero OAuth tokens; user identity and account data; billing records; audit logs; application source code; platform secrets.

Step 3 — Identify threats and vulnerabilities. For each asset, enumerate credible threat scenarios using the STRIDE model over the system data-flow (see A7 threat assessment methodology) plus real-world sources: penetration test findings, dependency and code scanning output, provider advisories, ACSC alerts, and incidents at comparable services.

Step 4 — Identify existing controls. Record the controls already reducing each scenario, distinguishing preventive (RLS policies, authorisation checks, Xero-enforced two-step verification, encryption, input validation), detective (audit trail, error alerting, log retention) and corrective (backup and restore, secret rotation, rollback).

Step 5 — Assess likelihood. Score 1–5 using exposure (is the path reachable by an unauthenticated user, an authenticated tenant, or only an operator?), attacker capability required, historical frequency in comparable services, and the strength of existing preventive controls.

Step 6 — Assess impact. Score 1–5 as the highest across five dimensions: confidentiality of customer client data (weighted highest — a cross-tenant exposure is by default Severe), integrity of financial data reaching a customer's ledger, availability of the service, regulatory consequence (notifiable breach), and client trust.

Step 7 — Determine and select treatment. Calculate inherent score (without controls) and residual score (with controls) as Likelihood × Impact. Apply the A4 thresholds. Select mitigate, transfer, avoid or accept. Mitigation is preferred wherever the control cost is proportionate to the residual reduction; acceptance always carries a written rationale and an expiry date.

Step 8 — Record, assign and re-test. Record the assessment in the risk register with a named owner and due date. Verify the effectiveness of implemented controls at the next review — a treatment is not closed until the control has been observed working (for example, a policy re-tested by an isolation check, or a restore verified by a restore test).

3. Assessment triggers

Full assessment annually. Targeted assessment on: new or changed subprocessor; material change to authentication, tenant isolation or file handling; any incident or near-miss; High or Critical penetration test or scanning findings; relevant regulatory change; onboarding an enterprise customer with a different risk profile.

4. NIST CSF 2.0 mapping

Function How this methodology addresses it
Govern Risk appetite in Step 1; ownership and review cadence in Step 8 and A4
Identify Asset inventory (Step 2), threat identification (Step 3), supplier risk (A4 §5)
Protect Control identification and mitigation selection (Steps 4 and 7)
Detect Detective controls assessed in Step 4; monitoring gaps recorded as accepted risks with expiry
Respond Incident scenarios feed the BCP/DR and the 24-hour notification commitment
Recover Backup, restore-test and recovery objectives assessed as corrective controls

5. Records

Each assessment records: date, scope, participants, assets considered, scenarios assessed with inherent and residual scores, treatment decisions with owners and dates, and the date of the next review. Records are retained for at least 3 years and are available to customers as evidence on request.