Risk management repeats as objectives, systems, suppliers and threats change. CSFaaS connects the context for a decision with its assessment, chosen response and follow-up work.

Framing guides criticality, threat, vulnerability, likelihood and impact assessment; response choices and ongoing monitoring feed further review.
An educational risk-management model. App records support the work; the diagram does not imply automated analysis. Open full-size diagram.

Frame

Establish the organisational objectives, scope and decision criteria. Maintain shared vocabulary in Databases and document the business context on each demand. Use the configured risk matrix consistently and explain material assumptions.

Assess

Create a demand, complete its intake information and submit it. Once accepted, identify the relevant scenarios and assess inherent, current and target risk. Link affected systems, third parties, policies and existing risks where they help explain the scope.

Respond

Record a response and justification for each risk. Use the configured analyst and assurance review stages when required. Create remediation plans for mitigation work, with clear responsibilities and a deadline.

Monitor

Use Risks and Remediation to follow open exposure, delivery, validation and review dates. Completing an assessment demand does not automatically mean every mitigation is implemented. Revisit assumptions when the environment changes and record a new assessment where a new decision is needed.