RACF-CC decision aid
Prioritise controls without losing sight of risk.
Compare likely risk reduction with the effort, disruption and cost of delivery. The result provides a consistent starting point for discussion—not an automatic decision or substitute for local risk assessment.
Questions about the worksheet? Contact us →
The scoring method
Risk benefit minus cumulative delivery burden
Risk Reduction is deliberately weighted twice as strongly as each individual delivery constraint. Implementation Effort, Operational Impact and Cost are cumulative because each represents a real constraint that a resource-limited organisation must absorb.
Suggested tiers
2 to 3 — high risk reduction with low cumulative delivery burden.
0 to 1 — valuable control requiring planned delivery, testing, sequencing or coordination.
−1 to −3 — requires redesign, funding, dependency work, compensating safeguards or significant planning.
−4 to −7 — outside the immediate baseline unless governance or local risk judgement requires another response.
The calculated tier identifies sequencing, not absolute importance. A lower-tier control may still address a serious security issue and should be considered alongside governance obligations, dependencies and professional judgement.
Interactive assessment
Score one proposed control
Use the rating guidance below and retain the evidence behind each judgement. Compare controls using the same assumptions and participants.
Interpretation safeguards
Use the score to improve decisions—not replace them
Do not reward easy work alone
A low-effort action with limited risk reduction should not automatically outrank a slightly harder control that meaningfully protects critical services.
Respond to mandatory risk
The governance flag identifies issues requiring timely action without changing the numeric tier. The response may be implementation, interim mitigation, escalation or explicit risk acceptance.
Challenge weak evidence
Low confidence does not change the arithmetic; it warns decision-makers to validate assumptions before committing resources.
Reassess after change
Repeat the assessment when threats, services, costs, dependencies or available controls change.
Worked comparison
Why security value still matters
| Control | Risk reduction | Effort | Impact | Cost | Score | Tier | Governance action |
|---|---|---|---|---|---|---|---|
| Require MFA for privileged accounts | 3 | 1 | 1 | 1 | 3 | First | No |
| Easy but low-impact control | 1 | 1 | 1 | 1 | −1 | Develop | No |
| Actively exploited vulnerability affecting a critical service | 3 | 3 | 3 | 3 | −3 | Develop | Required |
The comparison does not prove that MFA is appropriate in every context. It shows why low delivery burden should not be mistaken for high security value.
The actively exploited vulnerability remains in Develop on the arithmetic alone. The separate Governance Action flag makes the need for timely management action visible without changing its score or calculated tier.
Voluntary support
Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is entirely optional. Payment is handled on Stripe's secure site and does not provide additional access.
Continue with RACF-CC
Turn the result into owned, evidenced action.
Use the four-stage method to move from the priority decision through safe implementation and validation, supported by the relevant domain guidance.
