Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideClear answers about document workflow, asset valuation, risk decisions, FAIR analysis and ISO 27001 compliance.
PurpleWASP uses the asset register as the foundation for risk context. The asset supplies classification, ownership and confidentiality, integrity and availability values before the scenario-specific assessment begins.
Policies can be distributed to the entire organisation or a selected group. Other governed documents, such as standards and procedures, are distributed to specific groups according to department, location or role.
Reject returns the document with an overall mandatory reason. Request Changes allows the approver to highlight precise passages and attach review comments for revision.
The document type may require a quiz or other configured condition. Complete the quiz workflow and check the intended audience and publication date.
Use a minor change for limited wording or administrative changes, producing 1.1. Use a major change for material changes to scope, obligations or intent, producing 2.0.
Changing the organisation-wide scale between 3×3 and 5×5 recalculates related asset and risk values. Review thresholds, reports and priority records after the change.
The initial value comes from the asset. Scenario-specific likelihood, current controls and uncertainty can produce a higher inherent or current score as the assessment becomes more precise.
Appetite is the level the organisation is prepared to operate within. Tolerance is an upper boundary before stronger escalation. A risk can be within tolerance but above appetite, which still requires treatment or an approved exception.
The residual risk remains above appetite after treatment. PurpleWASP requires further reduction or a formal, time-bound exception approved by the designated authority.
The assessment reopens so the Risk Manager can change treatment and submit a new decision.
No. Reassessment creates a new version and preserves the previous assessment. The new version begins from the prior residual position and can carry forward relevant controls.
FAIR estimates frequency and loss magnitude for one defined threat scenario. Different threats have different frequencies, capabilities and consequences, so they should be assessed separately.
It is the average annual financial loss across the simulated periods. It is not a prediction that the organisation will lose exactly that amount in one year.
Where loss-event frequency is below certainty, the distribution can include years without a successful loss event and years with multiple losses.
The Statement of Applicability must explain why each excluded Annex A control is outside scope or unnecessary for the assessed risks. Generic or blank justification is not sufficient.
Yes. Approved policies and completed risk assessments can be linked to Annex A controls alongside other evidence, creating traceability across modules.
No. It is an operational indicator based on the information and statuses recorded in PurpleWASP. Certification decisions remain with the authorised audit and certification process.
Include the module, record ID, affected role, timestamp, expected and actual result, steps to reproduce, screenshots and the complete error text. Remove passwords, tokens and unnecessary personal data.
No questions match that search.