Free tool · No account required · Data stays in your browser

Resource Criticality Assessment

Determine what level of protection each resource requires. Assess every system, process, person, third party, and facility across three dimensions — Confidentiality, Integrity, and Availability — to produce a protection requirement per resource. The resources you assess here may be the same dependencies identified in your BIA, assessed from their own perspective.

Organisation details

Protection levels

CriticalC: Disclosure causes severe harm — financial crime, safety risk, mass data subject impact, or regulatory sanction with material consequence.
HighC: Disclosure causes significant harm to individuals or the organisation. Regulatory notification likely (e.g. GDPR breach reporting).
MediumC: Disclosure causes reputational damage or competitive disadvantage. Limited regulatory exposure.
LowC: Information is public or disclosure causes no meaningful harm. No regulatory consequence.

Each resource is rated independently on C, I, and A. The highest dimension determines the minimum protection level required.

R-001Untitled resourceSystem

Self-reported reference — not validated against a connected BIA

System — specific fields

Confidentiality

Medium

Disclosure causes reputational damage or competitive disadvantage. Limited regulatory exposure.

Integrity

Medium

Errors may go undetected for a period. Decisions based on corrupted data cause operational disruption.

Availability

Medium

Unavailability causes operational disruption. MTD measured in 24–72 hours.

Self-reported — not derived from a linked assessment. Verify consistency with your BIA.

Protection requirement

Highest dimension:Medium

Ready to export

1 resource · no critical · no high · no personal data · PDF includes cover, protection requirements matrix, and per-resource CIA detail

About Graello

Your RCA defines what protection each resource requires. Graello is where you act on it.

In Graello, each resource is connected to its controls, evidence, and the business services it supports. Protection goals are mapped to your control inventory, verified against evidence, and maintained in a traceable governance graph.

Request early access to Graello →
No data is stored. Everything lives in your browser and is cleared when you close the tab.