Perimeters #
Objective and access #
The Perimeters menu structures the analysis boundaries. Everyone can read; Creation, modification, and deletion require Risk Manager or higher.
Screen and fields #
The list allows search, creation and editing. A scope has name, description, parent and manager. The parent organizes the hierarchy; the person in charge bears the responsibility.
Life cycle #
Create perimeters before assets, risks and assessments. Check dependencies before archiving/deleting; the API refuses inter-tenant relationships.
Example #
“SaaS Production” can be a child of “Information System” and carry assets, risks and an ISO 27001 assessment.
Detailed procedure #
Create the root first, then the children. The name identifies the scope in the lists; the description specifies inclusions and exclusions; the parent constructs the hierarchy; the manager carries the magazine.
Before modification, measure the effect on assets, risks and valuations. Before deleting, search for all relationships. Prefer a stable scope rather than a tree structure reproducing each change in the organization chart.
Search and control #
Use search on name and description. Check absence of duplicate, parent of the same tenant, active manager and consistency with the framing documentation.
Common errors #
An invisible parent may belong to another tenant. A denied deletion often indicates a dependency. Too deep a hierarchy makes reports difficult to interpret.