Understanding risk helps keep your information safe. A risk assessment shows:
- what might go wrong
- how serious the harm could be
- the type of protection your data needs.
The Industry Data Classification Framework (IDCF) provides a simple way to assess risk and communicate the protection your data needs to others.
For more information, go to
Module 3: Risk assessment in the IDCF.
Protect your data
A risk assessment helps you understand your data by identifying:
- the type of data your organisation holds
- what could happen to it (adverse events)
- the effects this could have (consequences and impact).
When you understand these risks, you can choose the right level of protection, and use systems suitable for your data.
For more information, see
Data Security Levels.
Assess the risks
A simple data risk assessment looks at three main aspects:
- Confidentiality – who should be able to see the data
- Integrity – whether the data is accurate and reliable
- Availability – whether people who need the data can access it.
Different data carries different levels of risk. Considering these three aspects helps you understand how an adverse event could affect your organisation, or the people the data relates to.
The things that shape risk include:
- type of data – for example, personal information, financial records, technical or operational data
- scale – volume of data and how many people or systems it relates to
- currency – whether the data is current or outdated.
Not all data needs the same level of protection.
Anticipate adverse events
An adverse event is any incident that affects the confidentiality, integrity or availability of your data. These events can be:
- physical events, such as loss, theft or damage of a device
- cyber events, such as malware, phishing or unauthorised access
- authorised person events, such as mistakes, misuse or someone being tricked into sharing information (social engineering).
Knowing what events can occur makes it easier to plan ahead and reduce risk.
Consider consequences and impact
When something goes wrong with data, the effects can vary. Common consequences include:
- privacy harm
- loss of confidentiality
- reputational damage
- legal or regulatory issues
- financial loss
- operational disruption
- long-term impacts on business direction
- increased security risk.
One adverse event can cause more than one consequence, with varying levels of impact.
Impact describes how serious the harm from an adverse event could be, ranging from very low to very high. A low-impact event may cause a minor inconvenience. A very high-impact event may cause long-term harm to people and your organisation. Understanding the possible impact helps you decide the level of protection your data needs.
When a risk assessment is complete, the IDCF’s Data Security Levels (DSLs) provide a clear way to communicate the protection the data needs. This enables you to handle and store your data safely, both within an organisation and when shared with others.
For more information, see
Data Security Levels.