Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideReview Asset classification, CIA value, lifecycle and applicable Control context, then initiate the structured Risk workflow.
Open the Asset record and confirm its classification, CIA value, lifecycle status and ownership. Use the related Control and Risk context to understand how the Asset is governed elsewhere in PurpleWASP.
The details panel is organised into Overview, Controls, Vulnerabilities and Activity, with persistent Risk Details alongside the workspace. Use Guide this asset for an in-product walkthrough of the current layout.
PurpleWASP can surface Controls that apply to the Asset context. Where you are authorised to maintain Asset-level implementation, record the current state for that Asset rather than treating the organisation-wide Control status as proof of coverage.
Open the Vulnerabilities tab to review active findings grouped by provider vulnerability identity. Use Details to inspect description, remediation, CVEs, affected port/service, evidence and lifecycle history. Link selected groups to an existing Risk or create a normal Risk from the selected evidence when a new scenario is required.
Update the asset when it moves between states such as In Use, In Maintenance or Retired. Lifecycle labels support reporting and help teams identify assets that may need reassessment or retirement activity.
Risk assessment relies on the asset's confidentiality, integrity and availability value. Complete any missing values first.
Use the asset action that sends the record to the Risk Register.
Open Risk Management and verify that the asset appears for assessment with its inherited value and configured matrix.
When an administrator changes the organisation CIA model, related Asset and Risk values can be recalculated. Treat this as a governance change: review thresholds, reports and high-priority records after the change.
Complete required classification and CIA values, then confirm that your role can initiate risk assessment.
Refresh the register, clear filters and confirm that the send action completed successfully.