Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
32 / 34

Awakening Security

Appendices: Risk, Impact and Incident Templates and Standards Mapping

2 min read32 of 34Read it in the book · page 165

Ready-Made Templates and Standards Mapping

Risk Register Template

A single register for information risks and AI risks, with a column identifying which standard covers each risk. Fill in one row per risk, and review the register every quarter or after any significant change.

RiskAssetLikelihood × ImpactTreatmentOwner
Pre-release footage leakDailiesMedium × HighMitigate: encrypted drivesDigital imaging technician
Prompt injection into support agentAI agentHigh × MediumMitigate: tool isolationAI officer
Cloud provider outageAsset libraryLow × HighTransfer: second copyOperations manager

AI System Impact Assessment Template

ItemGuiding question
Purpose and intended useWhat is the task? Which uses are explicitly prohibited?
Affected partiesWho is the direct user? Who is touched by the outputs? Are any vulnerable groups among them?
DataWhere does it come from? Do we have the right to use it? Does it contain personal data?
Potential impactsBias? Misinformation? Harm to privacy, ownership or reputation?
ControlsHuman oversight? Disclosure? Usage limits? Drift monitoring?
DecisionLaunch, conditional launch, redesign, or stop.

AI Incident Report Template

  • Description: What did you notice? A harmful output, a leak in a prompt, or unexpected agent behaviour.
  • System and version: The tool or model name, its version, and its owner.
  • Impact: Who was affected? Did the output reach a client or the public?
  • Containment: Did you stop use? Were logs and prompts preserved as evidence?
  • Escalation: The system owner, the AI officer, and legal where needed.

Mapping ISO 42001 to Other Frameworks

FrameworkRelationship to ISO 42001
ISO 27001:2022The same structure (Clauses 4–10); covers the security of the data and systems AI depends on.
ISO 27701Privacy information management; complements personal-data controls in AI systems.
ISO 23894Guidance on AI risk management; a reference for the Clause 6.1 methodology.
ISO 42005Guidance on AI system impact assessment; details Clause 6.1.4.
NIST AI RMFIts four functions (Govern, Map, Measure, Manage) intersect with the system cycle.
EU AI ActLegal obligations by risk level; the system helps demonstrate compliance with them.

Tip: use ← → to move between sections.