Skip to main content
A risk is created in the Create Risk wizard and then moves through a five-phase lifecycle. Every phase change checks one substantive precondition.

Create a risk

Only Name is required. Assets can optionally be linked; at least one threat and one vulnerability must be chosen. The wizard does not ask for a relation type: Docusnap365 derives it on creation from the pair of risk and asset, threat, or vulnerability.
If you select assets in the Assets step, the Assessment step shows their protection need, per security objective with the highest level across all selected assets. For details on protection need, see Determine Protection Needs.

Perform the assessment

In the Assessment step you set Current Assessment and Target Assessment on the matrix. What risk assessment, risk level, and the treatment strategies mean is covered in Risk Management Fundamentals.
The assessment is optional when creating a risk. Only with all four values — likelihood, impact, and both target values — does the risk enter the Assessed phase; otherwise it starts as Identified.
The treatment strategy defaults to Mitigate; a responsible person can also be assigned after creation.
Creating, linking, and saving the description are separate operations. If only the linking of the selected assets, threats, or vulnerabilities fails, or only saving the description, the risk is still created. A toast reports what needs to be added on the detail page; if only some of the relations failed, it names exactly those. Add the missing parts there instead of running the wizard again — otherwise you create a second risk.

Carry it through the lifecycle

A jump across more than one phase is not possible — with one exception: from Monitoring, a phase change leads directly into Assessed without clearing the assessment values.
Every phase change requires a justification (up to 1000 characters). Without one, saving is canceled.
The risk matrix and treatment strategy are only editable in the Assessed phase. Change the assessment before you move on — otherwise the way back requires another, justification-bound phase change.

Completing or repeating the review

Complete Review records a review date with a required result text. Review + Reassess — available only in the Monitoring phase — additionally completes the review, resets the phase to Assessed, and clears all four assessment values, after you confirm a prompt.
Review + Reassess cannot be undone. The previous assessment survives only as a snapshot in the review history.
Manage Controls covers linking controls, which the Released phase requires. For a complete example, see the tutorial Carrying a Risk Through to Monitoring.