Risk Register
Template
Twelve columns covering STRIDE category, Likelihood x Impact scoring, mitigation, and ownership -- with six worked example rows spanning every STRIDE category, so the format is obvious before you add your own.
Twelve columns, six worked examples
Every STRIDE category appears at least once across the example rows, so you can see how the scoring and mitigation columns are meant to be filled in.
| ID | Asset | Threat | STRIDE | L | I | Score | Status |
|---|---|---|---|---|---|---|---|
| R-001 | Web Application | Attacker brute-forces passwords | Spoofing | 3 | 4 | 12 | Open |
| R-002 | Customer Database | PII exfiltrated via SQL injection | Tampering / Info Disclosure | 2 | 5 | 10 | In Progress |
| R-003 | Payment Webhook | Forged payment-confirmation webhook | Spoofing / Tampering | 2 | 4 | 8 | Open |
| R-004 | Admin Panel | Session token not invalidated on logout | Elevation of Privilege | 2 | 3 | 6 | Resolved |
| Column | Purpose |
|---|---|
| STRIDE Category | Which of the six STRIDE threat types this risk falls under |
| Likelihood / Impact (1-5) | Independent scores multiplied together for a 1-25 risk score |
| Mitigation / Control | What reduces or eliminates the risk, specific enough to verify |
| Control Owner | Who is accountable for implementing and maintaining the mitigation |
| Status / Dates | Whether it's open, in progress, or resolved, and when it was last reviewed -- the trail auditors actually look for |
Get the file
Opens directly in Excel, Google Sheets, Numbers, or LibreOffice Calc.
A spreadsheet holds your risks. It doesn't find them for you.
This template gives you the right columns. What it can't do is generate rows from your architecture, or prove a score is still accurate after the system changes.
-
Generated From Your Architecture
ThreatTree builds the register automatically from your DFD and Attack Trees -- every row traces back to a real component and attack path, not a row someone typed in from memory.
-
Standards-Based Control Mapping
Map each mitigation to ISO 27001, NIST SP 800-53, CIS Controls v8, PCI DSS v4.0, NIST CSF 2.0, or SOC 2 -- evidence auditors recognize by name.
-
Stays Current When the Architecture Changes
Update the DFD or Attack Tree and affected risk scores update with it -- no stale rows nobody remembers to revisit.
-
Board-Ready PDF Reports
Export the register alongside its source diagrams and attack trees as a single PDF -- not a spreadsheet screenshot pasted into a slide.
Questions about the template
What people ask before downloading.
Do I need to sign up to download this?
No. The download link goes straight to the file -- no email, no account, no form.
What software do I need to open a .csv file?
Any spreadsheet application -- Excel, Google Sheets, Numbers, or LibreOffice Calc all open CSV files directly.
How should I calculate the Risk Score column?
The template uses Likelihood x Impact, each scored 1-5, giving a range of 1-25. It's a simple, defensible starting point -- swap in your own scale (e.g. CVSS-based, or a 3-point scale) if your organization already has one.
How is this different from just using ThreatTree directly?
This template gives you the columns and the scoring logic. ThreatTree generates the register automatically from your Data Flow Diagram and Attack Trees, so every row traces back to a specific architecture element and attack path instead of being typed in by hand.
Generate the register automatically in ThreatTree
Free plan available -- no credit card required. No more hand-typed rows.