RACF-CC decision aid

Prioritise controls without losing sight of risk.

Compare likely risk reduction with the effort, disruption and cost of delivery. The result provides a consistent starting point for discussion—not an automatic decision or substitute for local risk assessment.

Questions about the worksheet? Contact us →

The scoring method

Risk benefit minus cumulative delivery burden

Risk Reduction is deliberately weighted twice as strongly as each individual delivery constraint. Implementation Effort, Operational Impact and Cost are cumulative because each represents a real constraint that a resource-limited organisation must absorb.

Priority score · range −7 to +3(Risk reduction × 2) − (Effort + Impact + Cost)

Suggested tiers

First

2 to 3 — high risk reduction with low cumulative delivery burden.

Next

0 to 1 — valuable control requiring planned delivery, testing, sequencing or coordination.

Develop

−1 to −3 — requires redesign, funding, dependency work, compensating safeguards or significant planning.

Review

−4 to −7 — outside the immediate baseline unless governance or local risk judgement requires another response.

The calculated tier identifies sequencing, not absolute importance. A lower-tier control may still address a serious security issue and should be considered alongside governance obligations, dependencies and professional judgement.

Interactive assessment

Score one proposed control

Use the rating guidance below and retain the evidence behind each judgement. Compare controls using the same assumptions and participants.

Risk reduction

How much meaningful cyber risk would this control reduce?

Implementation effort

How much specialist time, coordination and delivery work is required?

Operational impact

What disruption, accessibility concern or continuity risk could delivery create?

Cost

What is the relative financial burden for this organisation?

Interpretation safeguards

Use the score to improve decisions—not replace them

Do not reward easy work alone

A low-effort action with limited risk reduction should not automatically outrank a slightly harder control that meaningfully protects critical services.

Respond to mandatory risk

The governance flag identifies issues requiring timely action without changing the numeric tier. The response may be implementation, interim mitigation, escalation or explicit risk acceptance.

Challenge weak evidence

Low confidence does not change the arithmetic; it warns decision-makers to validate assumptions before committing resources.

Reassess after change

Repeat the assessment when threats, services, costs, dependencies or available controls change.

Worked comparison

Why security value still matters

ControlRisk reductionEffortImpactCostScoreTierGovernance action
Require MFA for privileged accounts31113FirstNo
Easy but low-impact control1111−1DevelopNo
Actively exploited vulnerability affecting a critical service3333−3DevelopRequired

The comparison does not prove that MFA is appropriate in every context. It shows why low delivery burden should not be mistaken for high security value.

The actively exploited vulnerability remains in Develop on the arithmetic alone. The separate Governance Action flag makes the need for timely management action visible without changing its score or calculated tier.

Voluntary support

Support Trends4You

Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.

Support is entirely optional. Payment is handled on Stripe's secure site and does not provide additional access.

Continue with RACF-CC

Turn the result into owned, evidenced action.

Use the four-stage method to move from the priority decision through safe implementation and validation, supported by the relevant domain guidance.