Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideAssess asset-related exposure qualitatively or quantify a specific threat scenario using FAIR.
Risk assessment links asset value, threats, vulnerabilities, controls, treatment and formal acceptance.
Start from an asset and describe vulnerabilities and threats.
Compare exposure with appetite and tolerance.
Mitigate, transfer, avoid, monitor, escalate or accept.
Complete within the rules or raise an exception.
Create a new version when conditions change.
Qualitative assessment supports consistent register prioritisation; FAIR quantifies one threat scenario financially.
Add vulnerabilities, threats and controls, then evaluate and treat the risk.
GovernanceProcess residual exposure above appetite and preserve assessment versions.
QuantitativeEstimate annual financial exposure using Monte Carlo simulation.
A risk can be within tolerance while still exceeding appetite. PurpleWASP requires further treatment or an approved exception before that assessment closes.
No guidance matches that search.