Help Centre module

Risk Management

Assess asset-related exposure qualitatively or quantify a specific threat scenario using FAIR.

Start with the workflow

From asset context to a governed decision

Risk assessment links asset value, threats, vulnerabilities, controls, treatment and formal acceptance.

1
Identify

Start from an asset and describe vulnerabilities and threats.

2
Evaluate

Compare exposure with appetite and tolerance.

3
Treat

Mitigate, transfer, avoid, monitor, escalate or accept.

4
Decide

Complete within the rules or raise an exception.

5
Reassess

Create a new version when conditions change.

Assessment paths

Choose the assessment that fits the decision

Qualitative assessment supports consistent register prioritisation; FAIR quantifies one threat scenario financially.

Important operating rules

Appetite and tolerance serve different purposes

A risk can be within tolerance while still exceeding appetite. PurpleWASP requires further treatment or an approved exception before that assessment closes.

  • Qualitative assessments can consider several threats.
  • FAIR scenarios analyse one specific threat at a time.
  • Rejected exceptions reopen the assessment.
  • Reassessment preserves previous versions and carries forward relevant controls.