Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideMaintain asset control and lifecycle information, then initiate a structured risk assessment from the asset record.
Open the asset record and confirm its classification, CIA value, lifecycle status and ownership. Related controls and risk details are presented in the same workspace.
PurpleWASP can present controls that apply to the asset type. Update each control to reflect its current implementation status. These values can influence compliance and the context available to risk assessors.
Update the asset when it moves between states such as In Use, In Maintenance or Retired. Lifecycle labels support reporting and help teams identify assets that may need reassessment or retirement activity.
Risk assessment relies on the asset's confidentiality, integrity and availability value. Complete any missing values first.
Use the asset action that sends the record to the Risk Register.
Open Risk Management and verify that the asset appears for assessment with its inherited value and configured matrix.
When an administrator changes the CIA matrix from 3×3 to 5×5, or back again, asset and risk values recalculate automatically. Treat this as a governance change: review thresholds, reports and high-priority records after the change.
Complete required classification and CIA values, then confirm that your role can initiate risk assessment.
Refresh the register, clear filters and confirm that the send action completed successfully.