Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideSet organisation context, security, users, roles, governed document, Asset, Risk, notification and module-access rules before operational rollout, including business objectives/processes used by Setup & Readiness and framework scoping.
Set organisation profile information such as name, permitted domain, country, sector, currency, locations and sensitivity labels. Review account-security options and confirm whether organisation AI features should be available.
Use Setup & Readiness to maintain the wider GRC context used by downstream work where available, including business objectives, business processes and process-to-Asset dependencies. These records give framework scope and governance decisions a reusable organisation context instead of repeating the same description in each module.
Create organisation roles, map them to PurpleWASP system permissions and assign users. Use least privilege and separate ownership, approval, exception and administrative responsibilities where appropriate.
Review the CIA scale, Asset value bands, reassessment periods, taxonomy, criticality labels, locations, tags and related Asset settings used by your deployment.
Review who can view and manage Control Management, Compliance and Third-Party Risk Management. Confirm that each workspace has accountable owners before enabling wider access.
Review both the organisation role and the mapped system/module permissions. Test with a fresh non-administrator login.
Review qualitative acceptance criteria, appetite, tolerance and any recent CIA/matrix changes.
Confirm that organisation AI features are enabled and that the user has access to the module/context being queried.