EBIOS RM
EBIOS RM (Expression des Besoins et Identification des Objectifs de Sécurité — Risk Manager) is the structured risk-management method published by the French national cybersecurity agency ANSSI. CyberGuard implements it natively: a study is not a generic risk assessment with extra fields, but its own object graph of feared events, stakeholders, risk origins, attack paths and operating modes, wired together the way the method prescribes.
Where to find it
Section titled “Where to find it”Risk → EBIOS RM in the sidebar.
Setting up a study
Section titled “Setting up a study”A study lives in a Domain and carries a Reference ID, a Version, a Status (planned, in progress, in review, done, deprecated), Authors, Reviewers, an Observation field, an ETA and a Due date. Three choices frame the work:
- Risk matrix — the scale used as a reference throughout the study.
- Reference entity — the organization the study is about.
- Quotation method — Manual or Express, controlling how much scoring you do by hand.
Opening a study shows the five workshops as tiles, each with its steps and their progress, so it is always obvious where the study stands and what comes next.
The five workshops
Section titled “The five workshops”Workshop 1: Framing and Security Foundation
Section titled “Workshop 1: Framing and Security Foundation”Define the study framework, set the business and technical perimeter by attaching the Assets that are pertinent, identify the Feared events — the undesirable outcomes on those assets, each rated by Severity — and determine the security foundation by attaching the compliance audits that serve as your baseline.
Workshop 2: Risk Origins
Section titled “Workshop 2: Risk Origins”Identify risk origins and targeted objectives, then evaluate each RO/TO couple on motivation, resources and activity to establish its Relevance, and select the couples the study will carry forward. Everything downstream flows from the selected couples.
Workshop 3: Strategic Scenarios
Section titled “Workshop 3: Strategic Scenarios”Map the ecosystem — the Stakeholders around your organization, each scored for Current dependency, Current penetration, Current maturity and Current trust, which the Ecosystem radar plots by Criticality. Then develop Strategic scenarios: high-level attack paths reaching a targeted objective through those stakeholders, each carrying a Likelihood. Finally, define the security measures that reduce ecosystem exposure.
Workshop 4: Operational Scenarios
Section titled “Workshop 4: Operational Scenarios”Prepare Elementary actions and their techniques, then build Operational scenarios on top of the selected attack paths: Operating modes assembled into a Kill chain whose stages run Reconnaissance, Initial Access, Discovery, Exploitation. Evaluate each scenario’s likelihood.
Workshop 5: Risk Treatment
Section titled “Workshop 5: Risk Treatment”Generate the risk assessment from the study — operational scenarios become risk scenarios, keeping a link back to their origin — then decide the treatment strategy, define the security measures, assess and document residual risks, and establish the monitoring framework. From this point the standard risk assessment and applied control machinery takes over, so EBIOS scenarios sit in the same register and action plan as everything else.
Outputs
Section titled “Outputs”Two views turn the study into something you can hand over:
- Report assembles the whole study into a readable document — study framing, assets and feared events with their severity, risk origins, the ecosystem radar, strategic scenarios and their attack paths, operational scenarios with their operating modes and kill chains, and the risk assessment with current and residual levels. Export PDF produces the deliverable.
- Visual Analysis renders the study as an interactive graph, so you can follow a chain from a risk origin through a stakeholder and an attack path to a feared event, and see which nodes carry the most connections.
Related
Section titled “Related”- Risk assessments — what workshop 5 generates.
- Assets — the business and supporting assets a study frames.
- Third parties — where the stakeholders in your ecosystem are managed.
- Risk matrices — the reference scale for the study.
