Risk Management
Assess Asset-related exposure qualitatively or with FAIR, incorporate manual and scanner-derived technical evidence, then govern treatment, exceptions, reassessment and linked Controls or third parties.
From context to a governed Risk decision
Risk assessment links Asset value, threats, vulnerabilities, operating Controls, treatment and formal acceptance while preserving lifecycle history.
Start from an Asset and define threats, manual weaknesses and linked technical exposure.
Assess likelihood/impact or quantify one FAIR threat scenario.
Plan mitigation, transfer, avoidance, monitoring, escalation or acceptance.
Evaluate residual exposure against appetite and govern any exception.
Create a new assessment version when conditions materially change.
Choose the assessment that fits the decision
Qualitative assessment supports consistent register prioritisation; FAIR quantifies one specific threat scenario financially.
Complete a qualitative Risk assessment
Add vulnerabilities, threats and current Controls, then evaluate and treat the Risk.
GovernanceManage Risk exceptions and reassessments
Govern residual exposure above appetite and preserve assessment versions.
Technical evidenceUse technical exposure in assessment and reassessment
Link scanner evidence, assess grouped technical vulnerabilities and preserve live-versus-historical evidence correctly.
QuantitativeComplete a FAIR quantitative assessment
Estimate annual financial exposure for one defined threat using Monte Carlo simulation.
Plan the rollout and operate the module
Download the practical first-time implementation handbook for this module.
Keep Risk semantics separate from connected module scores
Asset value, TPRM tier, Control implementation and Compliance status can inform Risk context, but they are not substitutes for the Risk assessment and its current/residual result.
- Qualitative assessments can consider multiple threats; FAIR scenarios analyse one specific threat at a time.
- Current Controls should reflect what is operating, while treatment actions represent planned changes.
- Rejected Risk exceptions return the exposure to treatment/reassessment rather than silently accepting it.
- Third-party and Control relationships provide context without transferring ownership of the Risk calculation.
- Scanner findings are linked as technical evidence and assessed in grouped form; they do not automatically become one Risk per finding.
- Download the Risk Management First-Time Implementation Handbook for rollout guidance and the Technical Documentation for architecture/operations detail.
No guidance matches that search.