Information
Threats
Actors
Results
Activity
Threats
Actors
Capacity
Capacity
Activities
Activities
Barriers
Barriers
Assets
Assets
Vulnerabilities
Vulnerabilities
SAFETAG Data Flow
While more completely defined below in the Risk Assessment and Agency Building sections,
a brief overview of the data flow components:
Actors Actors are the people connected to an organization include an organization's
staff, board members, contractors and partners. Actors could also include
volunteers, members of a broader community of practice, and even family members.
Actors also include potential adversaries of the organization such as competing
groups.
Activities Activities are the actions and processes of an organization. While most NGO
work revolves around mission-based concepts, activities also include things like
payroll.
Capacity Indicators of capacity include staff skills and a wide variety of resources that
an organization can draw from to affect change.
Barriers Barriers are specific challenges an organization faces that might limit or
block its capacity.
Assets Assets are most easily conceptualized as computer systems - laptops and
servers, but also include both the data stored on them and can also be services like
remote file storage, hosted websites, webmail, and more. Offline drives, USB sticks,
and even paper printouts of relevant or sensitive information can also be included
Vulnerabilities Vulnerabilities are specific flaws or attributes of an asset susceptible
to attack.
Threats A Threat is a specific, possible attack or occurrence that could harm the
organization. If a bucket of oily rags is a vulnerability, a fire is the threat - and
mitigations would be rules against leaving oily rags around as well as fire
extinguishers, smoke detectors, remote backup policies, and evacuation planning.
To make SAFETAG approachable, a core evaluation template which links together a series of
specific objectives, each with a variety of linked activities, that contribute towards the goals
and their required information needs is represented here. Experienced Auditors will likely
come up with their own approaches, and the SAFETAG project welcomes such
contributions.
Page 6 of 240