> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create and Assess Risks

> Capture a risk in the wizard, perform the assessment, and carry it through the phases of its lifecycle.

A risk is created in the *Create Risk* wizard and then moves through a
five-phase lifecycle. Every phase change checks one substantive precondition.

## Create a risk

Only *Name* is required. Assets can optionally be linked; at least one threat
and one vulnerability must be chosen. The wizard does not ask for a relation
type: Docusnap365 derives it on creation from the pair of risk and asset,
threat, or vulnerability.

<Tip>
  If you select assets in the *Assets* step, the *Assessment* step shows their
  protection need, per security objective with the highest level across all
  selected assets. For details on protection need, see
  [Determine Protection Needs](/docs/en/isms/protection-needs).
</Tip>

## Perform the assessment

In the *Assessment* step you set *Current Assessment* and *Target Assessment*
on the matrix. What risk assessment, risk level, and the treatment strategies
mean is covered in
[Risk Management Fundamentals](/docs/en/isms/understanding-risk-management).

<Note>
  The assessment is optional when creating a risk. Only with all four values —
  likelihood, impact, and both target values — does the risk enter the
  *Assessed* phase; otherwise it starts as *Identified*.
</Note>

The treatment strategy defaults to *Mitigate*; a responsible person can also
be assigned after creation.

<Warning>
  Creating, linking, and saving the description are separate operations. If
  only the linking of the selected assets, threats, or vulnerabilities fails, or
  only saving the description, the risk is still created. A toast reports what
  needs to be added on the detail page; if only some of the relations failed, it
  names exactly those. Add the missing parts there instead of running the wizard
  again — otherwise you create a second risk.
</Warning>

## Carry it through the lifecycle

| Phase | Allowed next phases | Precondition for the move |
| - | - | - |
| *Identified* | *Assessed* | — |
| *Assessed* | *In Treatment*, *Identified* | Likelihood and impact set, treatment strategy chosen |
| *In Treatment* | *Released*, *Assessed* | Owner set, at least one control linked (except with *Accept*) |
| *Released* | *Monitoring*, *In Treatment* | Review date set |
| *Monitoring* | *Released*, *Assessed* | — |

A jump across more than one phase is not possible — with one exception: from
*Monitoring*, a phase change leads directly into *Assessed* without clearing
the assessment values.

<Warning>
  Every phase change requires a justification (up to 1000 characters). Without
  one, saving is canceled.
</Warning>

<Warning>
  The risk matrix and treatment strategy are only editable in the *Assessed*
  phase. Change the assessment before you move on — otherwise the way back
  requires another, justification-bound phase change.
</Warning>

## Completing or repeating the review

*Complete Review* records a review date with a required result text.
*Review + Reassess* — available only in the *Monitoring* phase — additionally
completes the review, resets the phase to *Assessed*, and clears all four
assessment values, after you confirm a prompt.

<Warning>
  *Review + Reassess* cannot be undone. The previous assessment survives only as
  a snapshot in the review history.
</Warning>

## Related

[Manage Controls](/docs/en/isms/controls) covers linking controls, which the
*Released* phase requires. For a complete example, see the tutorial
[Carrying a Risk Through to Monitoring](/docs/en/isms/tutorial-risk).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.