RiskPilot Website FR GitHub

Risk register and governance #

Purpose and users #

The Risks menu transforms the context into evaluated scenarios. Risk manager creates and modifies; readers, listeners and managers consult according to their rights.

Create a scenario #

Enter title, description, family, method (simplified, ISO 27005 or EBIOS RM), scope, asset, threat, vulnerabilities, existing measures, responsible, processing, status and revision date. All relationships must belong to the tenant.

Understanding scores #

Each rating uses likelihood and impact from 1 to 5. Their product gives the score. The raw precedes the controls, the current reflects the observed situation and the residual the target after treatment.

Governance #

The policies define appetite, tolerance and capacity by domain/family. The portfolio consolidates risks; recommendations compare cost, burden and reduction. Formal acceptance requires decision, authorship and expiration. A campaign freezes a review snapshot.

The panel has four tabs with counters: Priorities, Policies, Acceptances and Campaigns. They complete the register displayed on the same page and do not constitute four separate menus.

Edit, archive and export #

Use search and filters, open the scenario, modify then re-evaluate. Archive preserves history. The CSV export is tenant-scoped and neutralizes formulas.

Errors and best practices #

An accepted status requires an approved acceptance that is still valid. Do not reduce a score without proof of control. Plan the next review and link treatments to actions.

Example #

The “CRM” asset exposed to phishing, with partial MFA, goes from a gross 20 to a current 12; full deployment creates a residual target 6.

See also #

Matrix · Action plans · Measures

Prerequisites #

Create the perimeter, asset, threat, vulnerabilities and measures that actually exist beforehand. The selected manager must be active and belong to the tenant. Also define family and analysis method conventions.

Description of fields #

FieldUse
Titleshort formulation of the scenario
Descriptionevent, causes, consequences and context
Familygrouping for governance and reporting
Methodsimplified, ISO 27005 or EBIOS RM
Scopeorganizational or technical scope
Vulnerabilitiesweaknesses actually applicable
Existing measuresoperational controls at the time of assessment
Treatmentavoid, reduce, transfer or accept
Statusworkflow status
Review datenext formal exam

Creation procedure #

  1. Formulate a risk event, without confusing it with a weakness.
  2. Choose the method and scope.
  3. Associate asset, threat, vulnerabilities and measures in the same tenant.
  4. Evaluate the gross without crediting the measurements.
  5. Evaluate the current based on proven controls.
  6. Define treatment and residual target.
  7. Assign the owner and review date.
  8. Save, then create the necessary actions.

Appetite and decisionsCompare current and residual assessment to palatability, tolerance and capacity policies. An excess must trigger reduction, transfer, avoidance or formal acceptance. Acceptance has a decider, a justification and an expiration; it does not remove the scenario. #

Campaigns and portfolio #

A campaign schedules the review and keeps a snapshot of the scores. The portfolio aggregates scenarios to identify concentrations, dominant families and differences in appetite. Recommendations help compare expected reduction, cost and burden.

Checks before validation #

  • relationships limited to the tenant;
  • measures actually deployed;
  • justified and consistent scores;
  • active owner;
  • treatment accompanied by actions;
  • unexpired acceptance if accepted status;
  • next review informed.

Common problems #

An object missing in a selector may belong to another scope/tenant or be archived. A score that does not change after selection of measures requires checking the evaluations entered: the presence of a control does not automatically calculate its effectiveness.