Effective risk management is a continuous, multifaceted process. It requires your organisation to work through four activities, again and again, as your environment changes.
1. Frame Risk
Establish the context for risk-based decisions: your business goals, the drivers behind your security effort, and the scope of what you assess. In CSFaaS this framing lives in your workspace catalogues and in the business context you attach to each demand.
2. Assess Risk
Identify and evaluate potential threats and vulnerabilities. Each risk assessment demand gathers the context, profiles the threats, and scores inherent, current and target risk against your risk matrix.
3. Respond to Risk
Decide and implement the appropriate treatment for each identified risk: mitigate, avoid, accept or transfer. Mitigation decisions turn into remediation plans with a responsible person and a due date.
4. Monitor Risk
Continuously track risk status through clear ownership, deadlines and feedback loops. Every demand, risk and remediation plan carries its own activity history, due date and SLA countdown, so nothing drifts silently.
5. How CSFaaS supports the process
The Risk Management solution maps each activity to a dedicated surface of the platform:
| Process activity | Where it happens in CSFaaS |
|---|---|
| Frame risk | Workspace catalogues (Databases module) and the business context sections of each demand |
| Assess risk | The Risk Demands module, from draft to completed assessment |
| Respond to risk | Risk responses on each risk, and Remediation Plans for mitigation work |
| Monitor risk | The Risk Registry, the Remediation Plans module, due dates with SLA countdowns, and analytics |
This integrated approach ensures your organisation can maintain a proactive and efficient risk management process, with every decision documented and traceable.
Source: NIST 800-161r1, p. 248 (the model applies to risk management generally, beyond supply-chain risk).