Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideAssess Asset-related exposure qualitatively or with FAIR, incorporate manual and scanner-derived technical evidence, then govern treatment, exceptions, reassessment and linked Controls or third parties.
Risk assessment links Asset value, threats, vulnerabilities, operating Controls, treatment and formal acceptance while preserving lifecycle history.
Start from an Asset and define threats, manual weaknesses and linked technical exposure.
Assess likelihood/impact or quantify one FAIR threat scenario.
Plan mitigation, transfer, avoidance, monitoring, escalation or acceptance.
Evaluate residual exposure against appetite and govern any exception.
Create a new assessment version when conditions materially change.
Qualitative assessment supports consistent register prioritisation; FAIR quantifies one specific threat scenario financially.
Add vulnerabilities, threats and current Controls, then evaluate and treat the Risk.
GovernanceGovern residual exposure above appetite and preserve assessment versions.
Technical evidenceLink scanner evidence, assess grouped technical vulnerabilities and preserve live-versus-historical evidence correctly.
QuantitativeEstimate annual financial exposure for one defined threat using Monte Carlo simulation.
Download the practical implementation handbook or the detailed technical reference for this module.
Practical first rollout covering governance settings, qualitative/FAIR assessment, technical exposure, treatment, exceptions and reassessment.
Technical referenceArchitecture, technical-evidence linkage, assessment snapshots, reassessment, treatment, security, deployment and regression reference.
Asset value, TPRM tier, Control implementation and Compliance status can inform Risk context, but they are not substitutes for the Risk assessment and its current/residual result.
No guidance matches that search.