RiskPilot Website FR GitHub

Security inventory #

Overview #

The inventory includes Perimeters, Assets, Threats, Vulnerabilities and Security measures. These catalogs form the context reused by the risk scenarios.

  1. Define the scope and its manager.
  2. Inventory the assets to protect.
  3. Describe threats and vulnerabilities without duplication.
  4. Record existing measures and their justified effectiveness.
  5. Compose the scenarios in the risk register.

Permissions and rules #

All authorized profiles view; Risk manager or higher creates, modifies and deletes. Each relationship is revalidated in the current organization.

Detailed pages #

Perimeters · Assets · Threats · Vulnerabilities · Measures

Inventory governance #

Define an owner per data family, a naming convention, a review frequency and authorized sources. Start small: items actually used in risks are better than a large, outdated catalog.

Quality control #

  • each asset belongs to a scope and has a manager;
  • threat and vulnerability remain two distinct concepts;
  • the severity is justified by a source;
  • the effectiveness of a measure is based on proof or a test;
  • no object duplicates an existing wording under a minor variant.

Review cycle #

Look for unaccounted for, unused, or old items. Correct the relationships before deletion. After a reorganization, check the scenarios, incidents, continuity, assessments and reports that reuse the inventory.