Lessons · Cybersecurity · severity from impact and scope
Severity: how bad, times how wide
Severity comes from two numbers, how bad the effect is (impact) and how much of the organisation it touches (scope), and multiplying them gives a score everybody rates the same way.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
Two analysts called the same incident 'medium' and 'critical' in the same hour, and the manager had to pick. With impact and scope written as numbers with definitions behind them, they would have agreed, and the argument would have been about the facts instead of the feeling.
How to think about it
Rate impact 1 to 5 from a written table (1 nuisance, 5 the business stops or data is exposed). Rate scope 1 to 5 (1 one user, 5 everybody). Multiply. Then read the band off the scale: 1 to 4 low, 5 to 9 medium, 10 to 14 high, 15 to 25 critical.
Worked example
Impact 4: customer data readable by somebody who should not see itFrom the table, not from how the morning feels.
Scope 3: one department, about 60 peopleHow wide, in the same 1 to 5 terms.
4 * 3 = 12, which is highOne number, and a band both analysts read the same way.
Write both numbers on the ticket, not just the bandSo the next person can disagree with the rating rather than with you.
Your turn
Impact 5, scope 2. Write the line that gives the severity score.
severity = 5 *
Solve one, graded on the server
The trap
Rating severity by how loudly it was reported. The chief executive's laptop and a warehouse laptop have the same impact table; the difference belongs in scope, if it belongs anywhere.