Risk management
Learn how the platform’s risk register tracks business and security risks while evaluating risk modeling systems, threats, and structured scenarios.
The platform supports two related modes of risk reasoning: a risk register for business or security risks pursued and structured risk assessments for the modeling of systems, threats, scenarios and risks resulting.
Risk register
Section entitled ‘Risk register’A risk record describes a risk, its current status and the context necessary for its assessment.
- measures to reduce or monitor risks;
- obligations that make treatment necessary;
- third-party assessments that identify vendor exposure;
- risk assessment scenarios explaining how the risk may arise.
Keep your risk statement easy to understand without relying on a single score. Record the activity or asset affected, the undesirable event and the likely consequence.
Threat-based assessments
“Threat-based assessments”A risk assessment can contain domains, nodes, limits, processes, threats and scenarios. Scenarios connect threats to one or more risks and make the assessment reasoning revisible.
Evaluations and registry entries have separate life cycles: evaluation documents are analyzed, while related risks are the elements that the organization tracks and handles over time.
Publication and review
Section entitled “Publication and review”Publishing risk records creates a revised list without hindering the program’s continued operation. Review risks when systems, suppliers, controls or business assumptions change. Use measures and tasks for treatment work instead of placing implementation details only in the risk description.