Outcome
After completing this guide, the risk record should contain:
- A clear scenario describing the threat, affected area and business consequence.
- An accountable risk owner and relevant category.
- A completed CIA or FAIR assessment appropriate to the decision being made.
- Existing controls, proposed actions and responsible owners.
- A documented decision to reduce the exposure or raise a risk exception.
- A review date and enough context for another reviewer to understand the assessment.
Before you begin
- Confirm that you have permission to create or edit risks.
- Identify the business owner who can accept accountability for the risk.
- Collect relevant asset, process, incident, vulnerability or control information.
- Decide whether a qualitative CIA assessment or a quantitative FAIR assessment is needed.
Write a scenario, not a topic.
“Ransomware” is a topic. A useful scenario explains what may happen,
what causes it and the consequence to the organisation.
1. Create the risk
- Open Risk Management and go to the risk register.
- Select the option to add a new risk.
- Enter a short title that distinguishes the scenario from similar risks.
- Describe the scenario using the cause, event and consequence.
- Select the appropriate risk category and assign the accountable owner.
- Link relevant assets, policies, frameworks or other records when those relationships are known.
- Save the initial record before opening the detailed assessment.
Example scenario structure
Because an internet-facing service remains vulnerable to a known exploit,
an external attacker could gain unauthorised access, resulting in service
disruption, investigation costs and potential disclosure of customer data.
| Field |
What good looks like |
| Title |
Specific enough to distinguish the scenario in reports and review meetings. |
| Description |
Explains the cause, event and business consequence without relying on unexplained acronyms. |
| Owner |
A person with authority to sponsor treatment or accept the remaining exposure. |
| Category |
Matches the organisation’s reporting taxonomy and is used consistently. |
2. Choose CIA or FAIR
PurpleWASP supports different assessment perspectives. Choose the method that
best fits the decision rather than completing both automatically.
| Use CIA when |
Use FAIR when |
| You need a structured qualitative view of confidentiality, integrity and availability impact. |
You need to express cyber or operational loss exposure in financial ranges. |
| The organisation uses likelihood and impact matrices for prioritisation. |
The decision requires assumptions about event frequency and loss magnitude. |
| The main goal is consistent comparison across a broad risk register. |
The main goal is investment, insurance, treatment or executive decision support. |
Do not force false precision.
A FAIR assessment is only as useful as the assumptions and ranges behind it.
Record uncertainty rather than presenting a single unsupported number.
3. Complete a CIA assessment
- Open the CIA assessment for the risk.
- Assess the potential effect on confidentiality, integrity and availability.
- Select likelihood and impact values using the organisation’s approved definitions.
- Review the calculated risk level against the scenario and supporting information.
- Add controls or actions that already reduce, or are intended to reduce, the exposure.
- Reassess the residual position after considering control effectiveness.
Assessment discipline
- Use the same time horizon across comparable risks.
- Separate current conditions from planned future controls.
- Do not lower likelihood or impact simply because an action has been proposed.
- Explain material judgement calls in the assessment notes.
4. Complete a FAIR assessment
FAIR decomposes the scenario into factors that influence loss-event frequency
and loss magnitude. Complete the inputs using defensible ranges and record the
basis for each important assumption.
- Confirm the loss event and the asset or process at risk.
- Estimate how often the relevant threat community may make contact.
- Assess the probability that contact becomes a successful loss event.
- Estimate primary losses, such as response, replacement, lost productivity or direct revenue impact.
- Estimate secondary losses where stakeholders may react, such as legal, regulatory or reputational consequences.
- Review the model output and test whether the ranges reflect the available evidence.
- Add controls and actions for this FAIR scenario rather than relying on controls recorded elsewhere.
Keep the scenario boundary stable.
Changing the threat, asset or consequence halfway through the assessment makes
the frequency and loss estimates difficult to interpret.
5. Add controls and actions
Controls describe what already changes the scenario. Actions describe work that
must still happen. PurpleWASP can associate items such as framework controls,
policies, evidence and treatment work with the scenario.
- Select Add control for this scenario or the equivalent action.
- Choose the appropriate item type, such as a framework control, policy, evidence record or treatment action.
- Select the specific record and explain how it affects the scenario.
- For actions, assign an owner and realistic due date.
- Record current effectiveness separately from expected future effectiveness.
- Save the item and confirm that it appears against the correct risk scenario.
| Item |
Use it to show |
| Framework control |
The recognised control requirement that should influence the risk. |
| Policy |
The approved organisational expectation relevant to the scenario. |
| Evidence |
Proof that a control operates, was tested or produced a result. |
| Treatment action |
Work that must be completed to change likelihood, impact or loss exposure. |
6. Record the decision
After reviewing the assessment and controls, choose the next governance path.
The CIA and FAIR workflows should both lead to a documented decision.
Reduce the risk
Use this path when further treatment is required.
- Record the selected treatment approach.
- Create specific actions with owners and due dates.
- Define the target position expected after the work is complete.
- Set a review date and monitor progress.
Raise a risk exception
Use this path when the remaining exposure will be accepted for a defined reason and period.
- Document the business justification.
- Record the current exposure and controls.
- Identify the approving authority.
- Set an expiry or review date.
- Capture any conditions or compensating controls attached to the approval.
An exception is not a permanent closure.
It should have an owner, approval, scope and review or expiry date.
7. Verify the record
Before leaving the assessment, confirm that:
- The title and scenario still describe the same risk that was assessed.
- The owner is accountable and the category supports reporting.
- The selected assessment method is complete.
- Controls and actions appear against the correct CIA or FAIR scenario.
- Action owners and dates are visible.
- The decision to reduce or raise an exception has been recorded.
- The review date reflects the urgency and expected pace of change.
Common problems
Controls do not load after selecting a domain
Confirm that the selected framework contains controls for that domain and that
your account can access them. Refresh the risk record after saving any related
CIA-side control, then retry. If the issue continues, capture the risk ID,
selected framework, domain and browser console error for support.
Saving a policy or evidence action does nothing
Check that all required fields are selected and that the source record is active.
Retry after refreshing the page. Record any visible validation or JavaScript error
before contacting support.
The score appears wrong
Recheck the likelihood, impact, inherent, residual and target fields. Confirm that
the correct matrix or FAIR assumptions were used and that proposed controls were
not treated as already effective.
The treatment action is missing
Confirm that the action was saved, assigned to an owner and is not hidden by a
status, owner, category or due-date filter.