Skip to content

Risk

The risk layer is where analyses are managed from definition to potential acceptance. Its shape follows the ISO 27005 workflow: identify scenarios, analyze them, let the matrix evaluate them, treat what is unacceptable, and formally accept what remains.

A risk assessment lives in a domain, optionally narrowed to a perimeter, and is bound to one risk matrix. It encompasses three steps:

  • Risk identification — defining the risk scenarios.
  • Risk analysis — assessing probability, impact and strength of knowledge for each scenario.
  • Risk evaluation — computed automatically from the selected matrix.

In CyberGuard, risk treatment is combined with the assessment rather than tracked as a separate phase: the controls that treat a scenario are attached directly to it, and their effect is what separates the risk levels below.

A risk scenario describes one unwanted event. It links the threats that materialize it, the assets it impacts, and the applied controls that mitigate it — split between existing controls and planned ones, because that split drives the level calculation. Scenarios can be created from inside an assessment or managed separately in the scenarios view.

Each scenario carries two ratings, each with its own probability, impact and computed level:

  • Current risk — the level today, given the controls already in place.
  • Residual risk — the level expected once the planned controls are implemented. This is the figure risk-acceptance decisions are made on.

A strength of knowledge indicator records how confident you are in the rating, and appears as a diamond marker on the matrix views. Consistency checks flag scenarios whose residual level exceeds the current one, or whose residual has been lowered without any applied control to justify the reduction.

For each scenario you record a treatment decision: mitigate it by planning additional applied controls, avoid the activity, transfer the risk, or accept it as it stands. Mitigation is the path that loops back into operations — the planned controls become real work items with owners and deadlines, and their completion is what makes the residual level honest.

Risk acceptance is the decision to tolerate a level of risk without further action. CyberGuard manages this as a formal workflow rather than a checkbox: an acceptance names the scenarios it covers and is routed to an approver for sign-off, giving management’s decision a recorded owner, date and expiry. The approver must hold the Approver role. Approaching acceptance expiry dates surface in the Analytics watch list, so tolerated risks come back for review instead of being forgotten.