Risk ID
RISK-001
Risk Title
Compromise of Administrator Credentials
Category (ISO 31000)
Operational
Risk Description
Risk of administrator credentials being compromised via phishing, brute force, or leaks.
Risk Type
Operational
Responsável
None
Status
Mitigating
Applicable Framework
Qriar IAM Security Framework
Ativo de Informação
None
Fonte de Ameaça
None
Data de Revisão
Not specified
Evento de Ameaça
None
Vulnerabilidade
None
Inherent Risk
12345
Catastrófico 5 10 15 20 25
Maior 4 8 12 16 20
Moderado 3 6 9 12 15
Menor 2 4 6 8 10
Insignif. 1 2 3 4 5
Rare Unlikely Possible Likely Almost Certain
Residual Risk
12345
Catastrófico 5 10 15 20 25
Maior 4 8 12 16 20
Moderado 3 6 9 12 15
Menor 2 4 6 8 10
Insignif. 1 2 3 4 5
Rare Unlikely Possible Likely Almost Certain
Descrição do Cenário
None
-
Frequência Mín.
-
Frequência Máx.
-
Magnitude Mín.
-
Magnitude Máx.
-
Expectativa de Perda Anual (BRL)
Resposta ao Risco
Modify
Response Status
Planned
Plano de Resposta
None
Notas de Mitigação
None
ID Risk Description Domínio
AUTH-001 Enforce Phishing-resistant MFA (FIDO2/CBA) for all administrative accounts, blocking SMS/voice. Authentication
AUTH-002 Enforce MFA for all users with Number Matching to mitigate MFA fatigue. Authentication
PAM-001 Eliminate permanent privileges (Zero Standing Privileges). Admin access only Just-In-Time and temporary. Privileged Access (PAM)
PAM-002 Separate accounts: adm-user (no email/web) for management and user for daily use. Privileged Access (PAM)
16/02/2026 00:12 qriar.demo
Risco atualizado status: Open -> Mitigating
{"likelihood": 4, "impact": 5, "status": "Open", "residual_likelihood": null, "residual_impact": null} {"likelihood": 4, "impact": 5, "status": "Mitigating", "residual_likelihood": null, "residual_impact": null}
Inherent Score
20
Critical
Residual Score
20
Critical
Probability (1-5)
4/5 4/5
Impact (1-5)
5/5 5/5
Created on
17/12/2025 03:54
Atualizado em
26/02/2026 06:45