Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideSet organisation, role, document, quiz, asset, risk and notification rules before operational teams begin using the platform.
Set company name, permitted email domain, country, sector, currency, locations and sensitivity labels. Review these values before using AI-generated content because location and sector can influence generated drafts.
Create organisation roles, map them to PurpleWASP system roles and assign users. Use least privilege and separate ownership, approval and exception-decision responsibilities where appropriate.
Manage the CIA scale, asset value bands, reassessment periods, asset classes and types, criticality labels, locations, location types, tags and custom controls.
Review both the organisation role and its mapping to system roles. Test with a non-administrator account.
Review qualitative acceptance criteria, appetite, tolerance and any recent matrix changes.