RiskPilot Website FR GitHub

GRC and ISMS concepts #

This page explains the vocabulary used in RiskPilot. GRC brings together governance, risk management and compliance. ISMS is the management system that organizes responsibilities, processes, evidence and improvements related to information security.

From assets to risk #

A perimeter delimits what is studied. An asset is an element that provides value and must be protected: information, service, application, material or process.

A threat is an event likely to cause harm. A vulnerability is a weakness that this threat can exploit. A security measure reduces plausibility, impact, or both.

RiskPilot assembles these elements into a scenario:

Périmètre → Actif → Menace → Vulnérabilité → Mesures → Évaluation → Traitement

Assess a risk #

Likelihood and impact are rated from 1 to 5. Their product gives a score from 1 to 25.

EvaluationQuestion answered
BruteWhat would the risk be without taking the measures into account?
CurrentWhat risk do we observe with the measures actually in place?
ResidualWhat risk will remain after the planned treatment?

Level thresholds are configurable per organization. A score facilitates comparison but does not replace analysis, justification and decision.

Appetite, tolerance and capacity #

  • Appetence: level of risk that the organization agrees to take to achieve its objectives.
  • Tolerance: admissible variation around this palatability.
  • Capacity: maximum level that the organization can absorb without compromising its continuity.

A RiskPilot acceptance is a formal, approved and time-limited decision. It does not eliminate the risk.

Compliance and evidence #

A repository contains requirements. An assessment assigns each a status, maturity and evidence. Evidence must be relevant, dated, attributable and protected.

The Statement of Applicability (SoA) explains which controls are applicable, why, and how they are implemented. An approved version is immutable; an evolution creates a revision.

Audit and CAPA #

An audit produces observations or non-conformities. The CAPA separates:

  1. root cause analysis;
  2. immediate correction;
  3. corrective action that avoids recurrence;
  4. preventive action, when relevant;
  5. the independent review of effectiveness.

Continuity #

The BIA analyzes the impacts of an interruption. The MTPD is the maximum tolerable duration, the RTO the target recovery time and the RPO the admissible data loss. RiskPilot imposes RTO ≤ MTPD.

Start with inventory, continue with risks, then actions and compliance.