HDDS2402 · Lesson 1 · Act 8第 1 課 · 單元 8

Classwork: the five-row risk register課堂作業:五行風險登記冊

Everything from the last three hours, on one page, in your own words. This is the artefact the whole lecture was building towards. 把過去三小時的全部內容,用你自己的文字寫在一頁上。這正是整節課所指向的成品。

The brief作業要求

Scenario情境

You have just been hired as the only person responsible for cybersecurity at a Hong Kong SME with 40 staff. It runs an online shop, holds about 40,000 customer records, uses one cloud provider, and outsources its payment page to a third party. 你剛獲聘為一間 40 人香港中小企唯一負責網絡安全的人員。該公司經營網店,持有約 40,000 筆客戶紀錄,使用單一雲端供應商,並將付款頁面外判予第三方。

Only 26% of Hong Kong SMEs have a dedicated security person. That is now you. Your first deliverable is a five-row risk register. 全港只有 26% 中小企設有專職保安人員。現在,那就是你。你的第一份交付成果,是一份五行風險登記冊。

Required coverage必須涵蓋

One row each with primary impact C, I and A. At least one control detective or corrective, not all five preventive. 須各有一行的主要影響為 CIA。至少一項措施須屬偵測性糾正性,不可全屬預防性。

Where to get realistic risks從何取得貼近現實的風險

Use today's evidence, not imagination. Three places to look:請運用今日的證據,而非憑空想像。三個可以入手的地方:

  1. The scenario itself. 40,000 records, one cloud provider, an outsourced payment page, 40 staff with logins. 情境本身。40,000 筆紀錄、單一雲端供應商、外判的付款頁面、40 名有登入權的員工。
  2. The four kinds of weakness. A software flaw, a misconfiguration, a process gap, a human factor: one row from each. 四類弱點。軟件缺陷、設定錯誤、流程缺口、人為因素:每類各寫一行。
  3. HKCERT's 2026 outlook, for what is rising: AI-driven attacks, weak AI governance (35% of AI-using firms put company data into AI tools), supply-chain gaps. HKCERT 2026 年展望,看甚麼正在上升:AI 驅動的攻擊、AI 管治薄弱(35% 使用 AI 的企業會把公司資料輸入 AI 工具)、供應鏈缺口。

What each column must contain各欄必須包含的內容

The columns are the chain. If you can fill a row, you have made a defensible security decision. 這些欄目就是那條鏈。若你能填滿一行,你便作出了一個站得住腳的保安決定。

Column欄目 Must contain必須包含 Exemplar cell示範內容

Your five-row register你的五行風險登記冊

Saved in this browser as you type. Nothing is sent anywhere. 內容會即時儲存在此瀏覽器,不會傳送到任何地方。

Complete完成度 0/5

How this is marked評分準則

Criterion準則 What earns the marks得分要求 Weight比重
Automatic mark loss必然失分
  • Residual risk written as "none" or left blank剩餘風險寫「無」或留空
  • A vulnerability sitting in the threat column把漏洞寫在威脅一欄
  • Evidence that is a promise, not an artefact證據寫成承諾,而非實際紀錄
  • All five controls preventive五項措施全屬預防性
What earns a distinction取得優異的關鍵

A row naming how your own control could fail or be bypassed, carried into residual risk. Nobody expects a perfect system, only that you know where yours is weak. 某一行能指出你的措施可能如何失效或被繞過,並寫入剩餘風險。無人期望系統完美,只期望你知道弱點所在。