> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Carrying a Risk Through to Monitoring

> Provide threat and vulnerability, assess the risk, link a recurring control and carry out the phase changes up to monitoring.

A risk goes through three phase changes from *Assessed* to *Monitoring*. Each
one has a precondition. We walk the chain through one example and name, for
every change, what blocks it.

## Starting point

Docusnap Sports GmbH runs its merchandise management on an SAP system. The
backup sits on the same network. Ransomware on the application server reaches
the backup as well. The protection need of the systems is already set — see
[Setting the Protection Need](/docs/en/isms/tutorial-protection-needs).

## 1. Provide threat and vulnerability

A risk needs at least one threat and one vulnerability. Both are entries of
their own, reusable across risks.

<Steps>
  <Step title="Import the threat">
    Under *ISMS › Risk Management › Threats*, *Import* opens the *Threat
    Catalog*. We search for "Ransomware" and take over the hit. Imported
    entries show their origin in the *Source* column.
  </Step>

  <Step title="Create the vulnerability">
    Under *Vulnerabilities* we create the entry "Backup not network-segregated"
    through *Vulnerability*, with *Category* and a description. There is no
    catalog for vulnerabilities.
  </Step>
</Steps>

## 2. Create and assess the risk

*Risk* opens the wizard. Name *Ransomware infection of the SAP database*; in
the *Assets* step the three systems of the merchandise management; in the
following steps the threat and the vulnerability. All steps:
[Assessing Risks](/docs/en/isms/assess-risks).

In the *Assessment* step we set both ratings: *Current Assessment* *Possible* ×
*Catastrophic*, *Target Assessment* *Unlikely* × *Major*. Strategy *Mitigate*.
In the *Owner* field we enter a person.

<Note>
  With all four assessment values, the risk comes into being in the *Assessed*
  phase. If a value is missing, it stands in *Identified*. The *Summary* step
  names the phase.
</Note>

## 3. Link a control

We open the risk, tab *Controls*. *Control* opens a dialog: link an existing
control or create a new one. We create *Offline backup of the SAP database*:
*Recurrence* *Recurring*, *Interval* 3, *Unit* *Months*.

<Note>
  Only a recurring control has the *Evidence* tab. With *One-time* it is missing.
  See [Evidencing Recurring Controls](/docs/en/isms/control-evidence).
</Note>

## 4. Carry out the phase changes

The lifecycle stands in the *Assessment* tab. Every change requires a reason in
the *Reason for the Phase Change* field.

| Change | Precondition |
| - | - |
| *Assessed* → *In Treatment* | likelihood and impact set, treatment strategy chosen |
| *In Treatment* → *Released* | owner assigned, at least one control linked (not with *Accept*) |
| *Released* → *Monitoring* | review date set |

If a precondition is not met, the change is not carried out. The hint names the
reason; where a control is missing, it offers a jump into the *Controls* tab.

<Warning>
  The risk matrix and the treatment strategy are editable only in the *Assessed*
  phase. Change the assessment before you leave the phase. Otherwise the way back
  leads through another phase change with a reason.
</Warning>

## 5. Working in monitoring

In *Monitoring*, the *Assessment* tab shows the state of the review: overdue,
due within the next 28 days, or not due.

*Complete Review* writes an entry into the *Review* tab with *Reviewed on*,
*Reviewed by* and *Result*. The result text is mandatory.

<Warning>
  If the review date is removed while in *Monitoring*, Docusnap365 resets the
  phase to *Assessed* on saving and reports this beforehand.
</Warning>

## 6. Reclassify after the review

Two paths lead from *Monitoring* back into *Assessed*:

| Path | Effect on the assessment |
| - | - |
| phase change to *Assessed* | assessment is kept |
| *Review + Reassess* | assessment is cleared; the previous state is saved as a snapshot in the *Review* tab |

<Warning>
  *Review + Reassess* cannot be undone. A confirmation appears before it runs. For
  a reclassification without losing the assessment, use the phase change.
</Warning>

## Next steps

Evidencing the control: [Evidencing Recurring Controls](/docs/en/isms/control-evidence).
The same control for a regulation objective:
[Assessing Objectives](/docs/en/isms/regulations).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.