GRC and ISMS concepts #
This page explains the vocabulary used in RiskPilot. GRC brings together governance, risk management and compliance. ISMS is the management system that organizes responsibilities, processes, evidence and improvements related to information security.
From assets to risk #
A perimeter delimits what is studied. An asset is an element that provides value and must be protected: information, service, application, material or process.
A threat is an event likely to cause harm. A vulnerability is a weakness that this threat can exploit. A security measure reduces plausibility, impact, or both.
RiskPilot assembles these elements into a scenario:
Périmètre → Actif → Menace → Vulnérabilité → Mesures → Évaluation → TraitementAssess a risk #
Likelihood and impact are rated from 1 to 5. Their product gives a score from 1 to 25.
| Evaluation | Question answered |
|---|---|
| Brute | What would the risk be without taking the measures into account? |
| Current | What risk do we observe with the measures actually in place? |
| Residual | What risk will remain after the planned treatment? |
Level thresholds are configurable per organization. A score facilitates comparison but does not replace analysis, justification and decision.
Appetite, tolerance and capacity #
- Appetence: level of risk that the organization agrees to take to achieve its objectives.
- Tolerance: admissible variation around this palatability.
- Capacity: maximum level that the organization can absorb without compromising its continuity.
A RiskPilot acceptance is a formal, approved and time-limited decision. It does not eliminate the risk.
Compliance and evidence #
A repository contains requirements. An assessment assigns each a status, maturity and evidence. Evidence must be relevant, dated, attributable and protected.
The Statement of Applicability (SoA) explains which controls are applicable, why, and how they are implemented. An approved version is immutable; an evolution creates a revision.
Audit and CAPA #
An audit produces observations or non-conformities. The CAPA separates:
- root cause analysis;
- immediate correction;
- corrective action that avoids recurrence;
- preventive action, when relevant;
- the independent review of effectiveness.
Continuity #
The BIA analyzes the impacts of an interruption. The MTPD is the maximum tolerable duration, the RTO the target recovery time and the RPO the admissible data loss. RiskPilot imposes RTO ≤ MTPD.
Recommended route #
Start with inventory, continue with risks, then actions and compliance.