Skip to content

Risk assessments

A risk assessment is a scenario-based evaluation of risk over a perimeter, following the ISO 27005 workflow. It is the container: it fixes the scope, the scale and the point in time, and holds the risk scenarios that do the actual work of describing what could go wrong. Everything downstream — the action plan, the analytics, the acceptance decisions — hangs off it.

Risk → Risk assessments in the sidebar.

An assessment lives in a Domain, which sets who can see it, and optionally narrows to a Perimeter — the service, product or process being studied. It is bound to one Risk matrix, which supplies the probability and impact scales and the lookup that turns them into a risk level. Matrices come from loaded libraries; most organizations settle on one official matrix, but you can choose a different one per assessment.

An optional Risk tolerance marks the threshold of tolerable risk level for this study, so scenarios above the line stand out.

  • Risk identification — write the risk scenarios.
  • Risk analysis — score each scenario’s probability, impact and strength of knowledge.
  • Risk evaluation — done for you, by looking the scores up in the matrix.

Risk treatment is not a separate phase in CyberGuard: the treatment decision and the controls that implement it live on the scenario itself.

An assessment carries a Version, a Status (planned, in progress, in review, done, deprecated), Authors, Reviewers, an Observation field and an ETA and Due date. Setting it to Locked freezes the study — scenarios can no longer be edited — which is how a signed-off assessment stays the record of what was decided.

Re-assessing is a duplication, not an overwrite. Duplicate copies the assessment and its scenarios into a new version, so last year’s figures stay readable next to this year’s.

The detail page lists the Associated risk scenarios and, below them, the Risk matrix view — the current and residual matrices side by side, with the inherent matrix as well when the inherent_risk feature flag is on.

Three buttons open the companion views:

  • Action plan groups the applied controls treating the scenarios, so the remediation programme reads as one plan with owners, statuses and ETAs; from there, Applied controls analytics, Budget overview and Flash mode drill further.
  • A remediation plan view lays the same information out scenario by scenario, listing each one’s existing controls and the extra controls planned for it — the shape you want when printing a treatment plan for review.
  • Analytics charts the study: Treatment distribution, Assets at risk, Threats breakdown, Strength of knowledge and Current risk level over time.

Export produces the assessment as PDF, CSV or Excel, and the action plan separately as PDF or Excel.

  • Duplicate — branch a new version.
  • Sync to actions — reconcile the scenarios’ residual scores with the applied controls actually in place. Turning on Automatic daily sync to actions on the assessment runs this for you.
  • Convert to Quantitative — seed a CRQ study from this assessment, carrying the scenarios across so the same risks can be re-expressed in money.
  • Request validation — route the assessment for formal sign-off, when validation flows are enabled.