Risk = threat × vulnerability
Threat
What can occur – ransomware, a power outage, an insider.
Vulnerability
What makes it possible – a missing backup, an open port, no four-eyes
principle.
Assessing: two points in one matrix
Assessment runs on likelihood times impact.
The product of the two axes is the risk assessment — one term with two states,
which the risk list and the matrix both carry as Current Assessment and Target
Assessment. The difference between the two is the Risk Reduction. A positive
value means the risk goes down.
The risk assessment turns into the risk level — Low, Medium, High or
Critical. It does not follow the risk assessment directly, but the value
normalized against the matrix size, checked against the configured zone
thresholds. Two tenants with different thresholds can therefore rate the same
risk assessment differently.
Assessment is optional while creating. It only counts as complete, though: only
once likelihood, impact and both target values are set does the risk come into
being in the lifecycle phase Assessed — otherwise in Identified.
Treating: four strategies
Mitigate is preselected; there is no empty selection. Only Mitigate leads to
work inside the product — it is carried out through
controls whose progress you track. The other three are
decisions that get justified and documented.
The lifecycle
Identified → Assessed → In Treatment → Released → Monitoring A treated risk moves into Monitoring and is reviewed again there. From monitoring, two paths lead back into Assessed, with different effects on the existing assessment:
To reclassify the risk without losing the existing assessment, use the ordinary
phase change. Review + Reassess is the path for a full reassessment
from scratch.
Some fields are editable only in the assessment phase. Outside it they carry the
hint “Editable only in the ‘Assessment’ lifecycle phase”; to change them, take the
risk back into that phase.