Free tool · No account required · Data stays in your browser
Determine what level of protection each resource requires. Assess every system, process, person, third party, and facility across three dimensions — Confidentiality, Integrity, and Availability — to produce a protection requirement per resource. The resources you assess here may be the same dependencies identified in your BIA, assessed from their own perspective.
Organisation details
Protection levels
Each resource is rated independently on C, I, and A. The highest dimension determines the minimum protection level required.
Self-reported reference — not validated against a connected BIA
System — specific fields
Confidentiality
MediumDisclosure causes reputational damage or competitive disadvantage. Limited regulatory exposure.
Integrity
MediumErrors may go undetected for a period. Decisions based on corrupted data cause operational disruption.
Availability
MediumUnavailability causes operational disruption. MTD measured in 24–72 hours.
Self-reported — not derived from a linked assessment. Verify consistency with your BIA.
Protection requirement
Ready to export
1 resource · no critical · no high · no personal data · PDF includes cover, protection requirements matrix, and per-resource CIA detail
About Graello
In Graello, each resource is connected to its controls, evidence, and the business services it supports. Protection goals are mapped to your control inventory, verified against evidence, and maintained in a traceable governance graph.
Request early access to Graello →