Shared catalogs give assessments consistent terms for business context, threats, impact and treatment. Review them before a large assessment campaign so equivalent scenarios are described in comparable ways.

Configure catalog values

Open Databases and use the Configuration index. Risk-related catalogs include business attributes, goals and their timelines, security drivers, data states, impact types, plan types, project phases, request priorities, risk categories and origins, threat actors and motivations, threat vectors and actions, STRIDE actions and victims quantification.

Shared catalogs also supply business units, functional domains, regions, data classifications and other cross-module values. Catalog editing requires the corresponding workspace permission.

Configure assessment scales separately

Open Settings for the Risk matrix and Impact matrix. Their dimensions, labels and configured values determine how scores are interpreted. Some reference choices remain read-only; a catalog editor is not a replacement for matrix configuration.

Use Risk demands settings to select the review process and priority-based SLA defaults. Workflow settings govern who reviews a demand; priority and due dates govern its scheduling.

Keep assessments comparable

Define what each classification means and avoid overlapping labels. Do not change shared scales merely to make an existing result appear lower. Review which matrix a risk uses before comparing it with another assessment, especially after configuration changes.