Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideIdentify vulnerabilities and threats, evaluate exposure against appetite and tolerance and document the selected treatment.
Complete a qualitative assessment for an asset, identify vulnerabilities and threats, consider existing controls, compare the result with appetite and tolerance and select an appropriate treatment.
Open the asset in the Risk Register and continue to Identification. Add vulnerabilities from the CVE catalogue or use non-CVE entries such as shadow IT, missing encryption or weak change control.
Add relevant threats and advanced persistent threats. Qualitative assessment can consider several threats together, unlike FAIR scenarios which analyse a specific threat individually.
Add implemented controls that currently change the risk scenario. PurpleWASP can link framework controls and policies already held elsewhere in the platform.
The platform calculates the assessment score and compares it with organisation thresholds.
Select the recommended or justified strategy: mitigate, transfer, avoid, monitor, escalate or accept. Use presets where useful, but adjust assumptions when the preset does not fit the scenario.
Add controls or actions that support the selected response and continue to Review.
Confirm that the narrative, score, treatment and evidence describe the same scenario. Complete the assessment when residual exposure is within the allowed decision rules, or continue to the exception process.
This can be expected as likelihood, control strength and uncertainty replace the initial asset-derived baseline with scenario-specific information.
Confirm that the framework has controls in that domain and that the control record is active and accessible.