Skip to content

EBIOS RM

EBIOS RM (Expression des Besoins et Identification des Objectifs de Sécurité — Risk Manager) is the structured risk-management method published by the French national cybersecurity agency ANSSI. CyberGuard implements it natively: a study is not a generic risk assessment with extra fields, but its own object graph of feared events, stakeholders, risk origins, attack paths and operating modes, wired together the way the method prescribes.

Risk → EBIOS RM in the sidebar.

A study lives in a Domain and carries a Reference ID, a Version, a Status (planned, in progress, in review, done, deprecated), Authors, Reviewers, an Observation field, an ETA and a Due date. Three choices frame the work:

  • Risk matrix — the scale used as a reference throughout the study.
  • Reference entity — the organization the study is about.
  • Quotation methodManual or Express, controlling how much scoring you do by hand.

Opening a study shows the five workshops as tiles, each with its steps and their progress, so it is always obvious where the study stands and what comes next.

Workshop 1: Framing and Security Foundation

Section titled “Workshop 1: Framing and Security Foundation”

Define the study framework, set the business and technical perimeter by attaching the Assets that are pertinent, identify the Feared events — the undesirable outcomes on those assets, each rated by Severity — and determine the security foundation by attaching the compliance audits that serve as your baseline.

Identify risk origins and targeted objectives, then evaluate each RO/TO couple on motivation, resources and activity to establish its Relevance, and select the couples the study will carry forward. Everything downstream flows from the selected couples.

Map the ecosystem — the Stakeholders around your organization, each scored for Current dependency, Current penetration, Current maturity and Current trust, which the Ecosystem radar plots by Criticality. Then develop Strategic scenarios: high-level attack paths reaching a targeted objective through those stakeholders, each carrying a Likelihood. Finally, define the security measures that reduce ecosystem exposure.

Prepare Elementary actions and their techniques, then build Operational scenarios on top of the selected attack paths: Operating modes assembled into a Kill chain whose stages run Reconnaissance, Initial Access, Discovery, Exploitation. Evaluate each scenario’s likelihood.

Generate the risk assessment from the study — operational scenarios become risk scenarios, keeping a link back to their origin — then decide the treatment strategy, define the security measures, assess and document residual risks, and establish the monitoring framework. From this point the standard risk assessment and applied control machinery takes over, so EBIOS scenarios sit in the same register and action plan as everything else.

Two views turn the study into something you can hand over:

  • Report assembles the whole study into a readable document — study framing, assets and feared events with their severity, risk origins, the ecosystem radar, strategic scenarios and their attack paths, operational scenarios with their operating modes and kill chains, and the risk assessment with current and residual levels. Export PDF produces the deliverable.
  • Visual Analysis renders the study as an interactive graph, so you can follow a chain from a risk origin through a stakeholder and an attack path to a feared event, and see which nodes carry the most connections.