> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Management Fundamentals

> What a risk consists of, how the matrix assesses it and which lifecycle it goes through.

In Docusnap365 a risk consists of at least one threat and one vulnerability,
carries an assessment in two states and goes through a lifecycle.

## Risk = threat × vulnerability

<CardGroup cols={2}>
  <Card title="Threat" icon="cloud-bolt">
    What can occur – ransomware, a power outage, an insider.
  </Card>

  <Card title="Vulnerability" icon="door-open">
    What makes it possible – a missing backup, an open port, no four-eyes
    principle.
  </Card>
</CardGroup>

Only the combination produces a risk: "ransomware" meets "no offline backup".
That pair is called a **scenario**.

This is why the creation wizard requires at least one threat **and** at least one
vulnerability for every risk. Both are captured beforehand as entries of their
own and are reusable — the same threat carries many risks, see
[Maintaining Threats and Vulnerabilities](/docs/en/isms/threats-vulnerabilities).

## Assessing: two points in one matrix

Assessment runs on likelihood times impact.

| Point | Meaning |
| - | - |
| *Current Assessment* | where it stands today |
| *Target Assessment* | where it should stand once treatment is done |

The product of the two axes is the **risk assessment** — one term with two states,
which the risk list and the matrix both carry as *Current Assessment* and *Target
Assessment*. The difference between the two is the **Risk Reduction**. A positive
value means the risk goes down.

The risk assessment turns into the **risk level** — *Low*, *Medium*, *High* or
*Critical*. It does not follow the risk assessment directly, but the value
normalized against the matrix size, checked against the configured zone
thresholds. Two tenants with different thresholds can therefore rate the same
risk assessment differently.

<Note>
  Assessment is optional while creating. It only counts as complete, though: only
  once likelihood, impact and both target values are set does the risk come into
  being in the lifecycle phase *Assessed* — otherwise in *Identified*.
</Note>

## Treating: four strategies

| Strategy | Meaning |
| - | - |
| *Mitigate* | implement controls to lower the risk |
| *Transfer* | pass the risk to a third party, for instance via insurance |
| *Avoid* | discontinue the activity or system that triggers the risk |
| *Accept* | knowingly bear and document the risk |

*Mitigate* is preselected; there is no empty selection. Only *Mitigate* leads to
work inside the product — it is carried out through
[controls](/docs/en/isms/controls) whose progress you track. The other three are
decisions that get justified and documented.

## The lifecycle

*Identified* → *Assessed* → *In Treatment* → *Released* → *Monitoring*

A treated risk moves into *Monitoring* and is reviewed again there. From
monitoring, two paths lead back into *Assessed*, with different effects on the
existing assessment:

| Path | Effect on the assessment values |
| - | - |
| ordinary phase change to *Assessed* | stay as they are |
| *Review + Reassess* | are cleared, after the previous state is captured as a snapshot |

To reclassify the risk without losing the existing assessment, use the ordinary
phase change. *Review + Reassess* is the path for a full reassessment
from scratch.

<Warning>
  *Review + Reassess* **cannot be undone**. Before anything is sent, Docusnap365
  asks back — "The lifecycle falls back to 'Assessment' and the existing
  assessments are cleared." The previous state then survives only as a snapshot in
  the review history, no longer as the assessment of the risk.
</Warning>

<Note>
  Some fields are editable only in the assessment phase. Outside it they carry the
  hint "Editable only in the 'Assessment' lifecycle phase"; to change them, take the
  risk back into that phase.
</Note>

## Related

The guided path from threat to strategy is in
[Assessing Risks](/docs/en/isms/assess-risks). All scales and values are in the
[ISMS Reference](/docs/en/isms/reference).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.