Risk Management guide

Use technical exposure in Risk assessment and reassessment

Link scanner evidence to a Risk, assess grouped technical vulnerabilities and preserve the evidence correctly across completed assessments and reassessments.

Risk Manager, Risk Owner or authorised assessor Approximately 10–20 minutes after the technical findings are available Updated 21 September 2026

Technical evidence supports a Risk; it is not the Risk itself

A scanner reports observations such as a Qualys QID on a host, port or service. PurpleWASP links selected observations to a business Risk and groups them by the technical vulnerability identity. This avoids creating hundreds of Risk records from one scan while keeping the evidence auditable.

2. Assess each linked technical vulnerability group

For each linked group, record the factors used by the qualitative Identification scenario:

Exploitability / likelihoodA 1–5 or organisation-scale judgement of how likely this technical weakness is to contribute to the scenario.
Control effectivenessA 0–1 reduction factor reflecting relevant controls already operating for this scenario.
Uncertainty %An explicit allowance for uncertainty in the scenario estimate.

A group is assessed once even when several findings, ports or services belong to the same source vulnerability.

3. Use Details to make an informed decision

Open Details to review the provider title/description, CVEs where mapped, remediation guidance, affected service/port, observation dates, occurrence count, scanner evidence and status history. This evidence is supporting context; the assessor still owns the business-scenario judgement.

4. Complete the assessment and preserve the snapshot

When a qualitative assessment is completed, PurpleWASP freezes the linked technical vulnerabilities and their exploitability, control-effectiveness and uncertainty values into that assessment version. Later provider changes do not rewrite the completed assessment evidence.

5. Reassess when conditions change

  1. Link any newly discovered technical evidence to the live Risk.
  2. Select Reassess Risk. PurpleWASP creates a new editable assessment version.
  3. During the live reassessment, Technical Exposure uses the current linked findings rather than the previous historical snapshot.
  4. Review and update the technical-vulnerability factors, threats, manual weaknesses and current Controls.
  5. Complete the reassessment to freeze a new historical snapshot.
Historical versus live: a completed assessment is read-only and shows the evidence captured at that time. A reassessment is live and shows the current linked technical posture until it is completed.

Common problems

Technical Exposure is empty during reassessment

Confirm you are in the live reassessment version rather than viewing a completed historical assessment. The current reassessment should show live linked evidence.

A linked finding is resolved

Keep the link when it remains relevant to assessment history. Resolution changes the current technical posture but does not erase the evidence or automatically close the Risk.

The same vulnerability appears on several ports

Use the grouped view. PurpleWASP assesses the technical vulnerability once while retaining the individual observations underneath it.