Risk Management guide

Create and assess a risk

Add a risk scenario to the register, complete the appropriate assessment, record controls and treatment actions, and document whether the remaining exposure will be reduced or formally accepted.

Risk Manager or authorised user Approximately 10–20 minutes Updated 24 July 2026

Outcome

After completing this guide, the risk record should contain:

  • A clear scenario describing the threat, affected area and business consequence.
  • An accountable risk owner and relevant category.
  • A completed CIA or FAIR assessment appropriate to the decision being made.
  • Existing controls, proposed actions and responsible owners.
  • A documented decision to reduce the exposure or raise a risk exception.
  • A review date and enough context for another reviewer to understand the assessment.

Before you begin

  • Confirm that you have permission to create or edit risks.
  • Identify the business owner who can accept accountability for the risk.
  • Collect relevant asset, process, incident, vulnerability or control information.
  • Decide whether a qualitative CIA assessment or a quantitative FAIR assessment is needed.
Write a scenario, not a topic. “Ransomware” is a topic. A useful scenario explains what may happen, what causes it and the consequence to the organisation.

1. Create the risk

  1. Open Risk Management and go to the risk register.
  2. Select the option to add a new risk.
  3. Enter a short title that distinguishes the scenario from similar risks.
  4. Describe the scenario using the cause, event and consequence.
  5. Select the appropriate risk category and assign the accountable owner.
  6. Link relevant assets, policies, frameworks or other records when those relationships are known.
  7. Save the initial record before opening the detailed assessment.

Example scenario structure

Because an internet-facing service remains vulnerable to a known exploit, an external attacker could gain unauthorised access, resulting in service disruption, investigation costs and potential disclosure of customer data.
Field What good looks like
Title Specific enough to distinguish the scenario in reports and review meetings.
Description Explains the cause, event and business consequence without relying on unexplained acronyms.
Owner A person with authority to sponsor treatment or accept the remaining exposure.
Category Matches the organisation’s reporting taxonomy and is used consistently.

2. Choose CIA or FAIR

PurpleWASP supports different assessment perspectives. Choose the method that best fits the decision rather than completing both automatically.

Use CIA when Use FAIR when
You need a structured qualitative view of confidentiality, integrity and availability impact. You need to express cyber or operational loss exposure in financial ranges.
The organisation uses likelihood and impact matrices for prioritisation. The decision requires assumptions about event frequency and loss magnitude.
The main goal is consistent comparison across a broad risk register. The main goal is investment, insurance, treatment or executive decision support.
Do not force false precision. A FAIR assessment is only as useful as the assumptions and ranges behind it. Record uncertainty rather than presenting a single unsupported number.

3. Complete a CIA assessment

  1. Open the CIA assessment for the risk.
  2. Assess the potential effect on confidentiality, integrity and availability.
  3. Select likelihood and impact values using the organisation’s approved definitions.
  4. Review the calculated risk level against the scenario and supporting information.
  5. Add controls or actions that already reduce, or are intended to reduce, the exposure.
  6. Reassess the residual position after considering control effectiveness.

Assessment discipline

  • Use the same time horizon across comparable risks.
  • Separate current conditions from planned future controls.
  • Do not lower likelihood or impact simply because an action has been proposed.
  • Explain material judgement calls in the assessment notes.

4. Complete a FAIR assessment

FAIR decomposes the scenario into factors that influence loss-event frequency and loss magnitude. Complete the inputs using defensible ranges and record the basis for each important assumption.

  1. Confirm the loss event and the asset or process at risk.
  2. Estimate how often the relevant threat community may make contact.
  3. Assess the probability that contact becomes a successful loss event.
  4. Estimate primary losses, such as response, replacement, lost productivity or direct revenue impact.
  5. Estimate secondary losses where stakeholders may react, such as legal, regulatory or reputational consequences.
  6. Review the model output and test whether the ranges reflect the available evidence.
  7. Add controls and actions for this FAIR scenario rather than relying on controls recorded elsewhere.
Keep the scenario boundary stable. Changing the threat, asset or consequence halfway through the assessment makes the frequency and loss estimates difficult to interpret.

5. Add controls and actions

Controls describe what already changes the scenario. Actions describe work that must still happen. PurpleWASP can associate items such as framework controls, policies, evidence and treatment work with the scenario.

  1. Select Add control for this scenario or the equivalent action.
  2. Choose the appropriate item type, such as a framework control, policy, evidence record or treatment action.
  3. Select the specific record and explain how it affects the scenario.
  4. For actions, assign an owner and realistic due date.
  5. Record current effectiveness separately from expected future effectiveness.
  6. Save the item and confirm that it appears against the correct risk scenario.
Item Use it to show
Framework control The recognised control requirement that should influence the risk.
Policy The approved organisational expectation relevant to the scenario.
Evidence Proof that a control operates, was tested or produced a result.
Treatment action Work that must be completed to change likelihood, impact or loss exposure.

6. Record the decision

After reviewing the assessment and controls, choose the next governance path. The CIA and FAIR workflows should both lead to a documented decision.

Reduce the risk

Use this path when further treatment is required.

  • Record the selected treatment approach.
  • Create specific actions with owners and due dates.
  • Define the target position expected after the work is complete.
  • Set a review date and monitor progress.

Raise a risk exception

Use this path when the remaining exposure will be accepted for a defined reason and period.

  • Document the business justification.
  • Record the current exposure and controls.
  • Identify the approving authority.
  • Set an expiry or review date.
  • Capture any conditions or compensating controls attached to the approval.
An exception is not a permanent closure. It should have an owner, approval, scope and review or expiry date.

7. Verify the record

Before leaving the assessment, confirm that:

  • The title and scenario still describe the same risk that was assessed.
  • The owner is accountable and the category supports reporting.
  • The selected assessment method is complete.
  • Controls and actions appear against the correct CIA or FAIR scenario.
  • Action owners and dates are visible.
  • The decision to reduce or raise an exception has been recorded.
  • The review date reflects the urgency and expected pace of change.

Common problems

Controls do not load after selecting a domain

Confirm that the selected framework contains controls for that domain and that your account can access them. Refresh the risk record after saving any related CIA-side control, then retry. If the issue continues, capture the risk ID, selected framework, domain and browser console error for support.

Saving a policy or evidence action does nothing

Check that all required fields are selected and that the source record is active. Retry after refreshing the page. Record any visible validation or JavaScript error before contacting support.

The score appears wrong

Recheck the likelihood, impact, inherent, residual and target fields. Confirm that the correct matrix or FAIR assumptions were used and that proposed controls were not treated as already effective.

The treatment action is missing

Confirm that the action was saved, assigned to an owner and is not hidden by a status, owner, category or due-date filter.

Open Risk troubleshooting Contact PurpleWASP support