Free download — no signup required

Risk Register
Template

Twelve columns covering STRIDE category, Likelihood x Impact scoring, mitigation, and ownership -- with six worked example rows spanning every STRIDE category, so the format is obvious before you add your own.

No email required Opens in Excel, Sheets, or Numbers Free for commercial use
What's inside

Twelve columns, six worked examples

Every STRIDE category appears at least once across the example rows, so you can see how the scoring and mitigation columns are meant to be filled in.

ID Asset Threat STRIDE L I Score Status
R-001 Web Application Attacker brute-forces passwords Spoofing 3 4 12 Open
R-002 Customer Database PII exfiltrated via SQL injection Tampering / Info Disclosure 2 5 10 In Progress
R-003 Payment Webhook Forged payment-confirmation webhook Spoofing / Tampering 2 4 8 Open
R-004 Admin Panel Session token not invalidated on logout Elevation of Privilege 2 3 6 Resolved
Column Purpose
STRIDE CategoryWhich of the six STRIDE threat types this risk falls under
Likelihood / Impact (1-5)Independent scores multiplied together for a 1-25 risk score
Mitigation / ControlWhat reduces or eliminates the risk, specific enough to verify
Control OwnerWho is accountable for implementing and maintaining the mitigation
Status / DatesWhether it's open, in progress, or resolved, and when it was last reviewed -- the trail auditors actually look for

Get the file

Opens directly in Excel, Google Sheets, Numbers, or LibreOffice Calc.

Download .csv
Where a static spreadsheet stops

A spreadsheet holds your risks. It doesn't find them for you.

This template gives you the right columns. What it can't do is generate rows from your architecture, or prove a score is still accurate after the system changes.

  • Generated From Your Architecture

    ThreatTree builds the register automatically from your DFD and Attack Trees -- every row traces back to a real component and attack path, not a row someone typed in from memory.

  • Standards-Based Control Mapping

    Map each mitigation to ISO 27001, NIST SP 800-53, CIS Controls v8, PCI DSS v4.0, NIST CSF 2.0, or SOC 2 -- evidence auditors recognize by name.

  • Stays Current When the Architecture Changes

    Update the DFD or Attack Tree and affected risk scores update with it -- no stale rows nobody remembers to revisit.

  • Board-Ready PDF Reports

    Export the register alongside its source diagrams and attack trees as a single PDF -- not a spreadsheet screenshot pasted into a slide.

FAQ

Questions about the template

What people ask before downloading.

Still have questions?

We usually reply within a day.

Get in touch
Do I need to sign up to download this?

No. The download link goes straight to the file -- no email, no account, no form.

What software do I need to open a .csv file?

Any spreadsheet application -- Excel, Google Sheets, Numbers, or LibreOffice Calc all open CSV files directly.

How should I calculate the Risk Score column?

The template uses Likelihood x Impact, each scored 1-5, giving a range of 1-25. It's a simple, defensible starting point -- swap in your own scale (e.g. CVSS-based, or a 3-point scale) if your organization already has one.

How is this different from just using ThreatTree directly?

This template gives you the columns and the scoring logic. ThreatTree generates the register automatically from your Data Flow Diagram and Attack Trees, so every row traces back to a specific architecture element and attack path instead of being typed in by hand.

Generate the register automatically in ThreatTree

Free plan available -- no credit card required. No more hand-typed rows.