RiskPilot Website FR GitHub

Vulnerabilities #

Objective and fields #

A vulnerability is an exploitable weakness. The menu manages name, description, category, source, severity and assigned assets.

Procedure #

Risk manager creates or modifies the weakness, associates only the tenant's assets and then uses it in the scenarios. Search helps avoid duplicates; check links before deletion.

Good practice #

Distinguish between lasting weakness and one-off events. Document the source without storing secrets, then combine measures that actually reduce exposure.

Description of fields #

Name and description explain the weakness; category and source facilitate qualification; severity prioritizes the review; Affected assets limits the weakness to the elements actually affected.

Complete procedure #

Check if the weakness already exists, select the tenant's assets, document the source then save. Link it to the relevant scenarios and the measures that compensate for it. Remove an asset only after verifying its risks.

Example #

“No-Second-Factor Authentication” affects the admin portal. The associated threat may be credential theft; the measurement is the MFA TOTP.

Controls #

An assetless vulnerability may be a catalog item, but it does not yet describe an exposure. Do not copy any secrets, confidential evidence, or unnecessary actionable details into the description.