RiskPilot Website FR GitHub

Security measures #

Lens and screen #

Measures reduce likelihood or impact. The form includes name, description, type, category, effectiveness, deployment and status.

Life cycle #

Risk manager creates and maintains. Effectiveness expressed as a percentage must be supported and reviewed; the status does not replace a control test. Before deletion, check related risks, actions and requirements.

Relationships #

Existing metrics contribute to the current/residual score. They can be linked to an action, to a line of SoA, to requirements and to an effectiveness test.

Description of fields #

The type and category describe the nature of the control. Effectiveness (%) expresses the estimated effect and must be proven. Deployment describes actual progress; the status allows monitoring of the life cycle.

Complete procedure #

Create a measure with a verifiable objective, choose type and category, document its deployment, then assign conservative effectiveness. Link it to risks and requirements, and plan a design or operational effectiveness test.

Example #

“MFA of privileged accounts”: preventive control, partial deployment, initial effectiveness justified by the coverage rate. An action carries the rest of the deployment.

Errors and best practices #

Do not confuse planned control with operational control. A high percentage without evidence distorts the current risk. After a failed test, reassess effectiveness, risks and associated actions.