Configuring the Risk Module
Basic configurations such as Risk Classification, Appetite and Calculation
Introduction
There are four steps to set up the Risk module. Some of these steps are mandatory, while some are optional. Let's begin with the mandatory steps:
- Create your Risk Classification Schema
- Select a Calculation Method
- Configure your Risk Matrix
- Configure your Risk Treatment Options
All the configuration steps mentioned above are foundational. This means that once you define them, you will most likely try to avoid changing them as much as possible. If you upload 500 risks and suddenly realize that you want a different classification of risk calculation, you will need to reclassify every risk on the system. Inconvenient.
Risk Classification
You need to define a risk classification that will suit your risk calculation. Review the risk calculations documentation and choose the method that suits you best, then follow these steps on the Risk module (any of them):
- Go to Risk Module (Asset, Third Party or Business) / Settings / Risk Classifications
- Click on “Add New”
- Assuming that a fresh installation is used, you will first need to create a Type (first field). Click “Add” and create your first risk classification type. (For example: Likelihood, Impact, etc.)
- You can then create a classification for this type. (For example: High, Low, etc.) You will need a numeric value that will be used on the Risk Score.
- Create new classifications for the type created in step three. Once you are done, you can create a new classification type and continue the process.
Risk Calculation Method
You can now go and choose your Risk Calculation:
- Go to Settings / Risk Calculation Method
- Choose the Risk Calculation method (you need to select the checkbox option)
- Configure the Risk Calculation by choosing the Risk Classifications
- Save
Risk Appetite
With the exception of Magerit, all other risk calculations support matrixes configured at the “Threshold” tab. We strongly advise you to use Thresholds.
- Check the Threshold method.
- For every combination on the matrix, choose a title, description, and colour.
- Optional: if you have a default threshold, you can use the top left corner and avoid configuring all of the combinations. This is typically the case for the lower threshold of the matrix.
If you are using Magerit, you cannot use the Threshold method. You need to use the numerical method. Check the tab and choose a number at which risks will be considered higher than the organizational appetite.
Treatment Options
You will need to set for every risk what treatment strategy you wish to apply, your options are: Avoid, Transfer, Mitigate and Accept. You will also need to define what treatment objects you want to link: Controls, Policies, Projects and Exceptions.
On all three Risk modules, under "Settings > "Treatment Options" you can define for each treatment strategy which mitigation options will be mandatory or optional. This is useful to make sure treatment across your risks is done consistently.
Playlist
- Episode 1Introduction to Risk Management7 mins left
- Episode 2Problem vs. Solution Principle5 mins left
- Episode 3Typical Risk Questions8 mins left
- Episode 4Risk Calculation Methods4 mins left
- Episode 5Configuring the Risk Module2 mins left
- Episode 6Risk Management Related Modules1 min left
- Episode 7Identifying Risks Inputs7 mins left
- Episode 8Identifying Risk Solutions5 mins left
- Episode 9Creating Risks4 mins left
- Episode 10Threats & Vulnerabilities1 min left
- Episode 11Reviewing Risks7 mins left