Skip to main content
In Docusnap365 a risk consists of at least one threat and one vulnerability, carries an assessment in two states and goes through a lifecycle.

Risk = threat × vulnerability

Threat

What can occur – ransomware, a power outage, an insider.

Vulnerability

What makes it possible – a missing backup, an open port, no four-eyes principle.
Only the combination produces a risk: “ransomware” meets “no offline backup”. That pair is called a scenario. This is why the creation wizard requires at least one threat and at least one vulnerability for every risk. Both are captured beforehand as entries of their own and are reusable — the same threat carries many risks, see Maintaining Threats and Vulnerabilities.

Assessing: two points in one matrix

Assessment runs on likelihood times impact. The product of the two axes is the risk assessment — one term with two states, which the risk list and the matrix both carry as Current Assessment and Target Assessment. The difference between the two is the Risk Reduction. A positive value means the risk goes down. The risk assessment turns into the risk level — Low, Medium, High or Critical. It does not follow the risk assessment directly, but the value normalized against the matrix size, checked against the configured zone thresholds. Two tenants with different thresholds can therefore rate the same risk assessment differently.
Assessment is optional while creating. It only counts as complete, though: only once likelihood, impact and both target values are set does the risk come into being in the lifecycle phase Assessed — otherwise in Identified.

Treating: four strategies

Mitigate is preselected; there is no empty selection. Only Mitigate leads to work inside the product — it is carried out through controls whose progress you track. The other three are decisions that get justified and documented.

The lifecycle

Identified → Assessed → In Treatment → Released → Monitoring A treated risk moves into Monitoring and is reviewed again there. From monitoring, two paths lead back into Assessed, with different effects on the existing assessment: To reclassify the risk without losing the existing assessment, use the ordinary phase change. Review + Reassess is the path for a full reassessment from scratch.
Review + Reassess cannot be undone. Before anything is sent, Docusnap365 asks back — “The lifecycle falls back to ‘Assessment’ and the existing assessments are cleared.” The previous state then survives only as a snapshot in the review history, no longer as the assessment of the risk.
Some fields are editable only in the assessment phase. Outside it they carry the hint “Editable only in the ‘Assessment’ lifecycle phase”; to change them, take the risk back into that phase.
The guided path from threat to strategy is in Assessing Risks. All scales and values are in the ISMS Reference.