Catalogues define the vocabulary of your risk process: the risk categories, threat actors, impact types and priorities every assessment picks from. Tailoring them keeps your assessments consistent and aligned with how your organisation actually talks about risk.

1. Where to edit catalogues

Catalogues are managed in the Databases module, under the Configuration Catalogs tab. The catalogue list is grouped by the domain each catalogue serves (Risk, Policy, System, Third Party, or shared across modules); select a catalogue to open its editor and add, rename or describe entries.

Note: Editing catalogues requires the Catalog Management permission. The workspace owner and Account Manager can always edit; other members need the permission granted through their role in Settings, Users.

2. Risk management catalogues

These catalogues feed the risk demand and risk assessment forms. Adjust them to fit your environment, or keep the defaults:

  • Business Attributes
  • Business Drivers for Security
  • Business Goals and Objectives and Business Goals and Objectives Timelines
  • Data State Options
  • Impact Types
  • Plan Types
  • Project phase Levels
  • Request Priority Levels
  • Risk Categories and Risk Origins
  • Threat Actors, Threat Actor Motivations, Threat Vectors, Threat Actions and Threat Actions STRIDE
  • Victims Quantification

3. Shared catalogues used by risk demands

Some catalogues are cross-cutting: they describe your organisation and are shared with other modules, so configure them once during your initial setup:

  • Business Units
  • Functional Domains
  • Regions
  • Data Classification Options
  • Architectural Domains
  • Control Category

4. Fixed scales

A few risk catalogues are fixed scales and are shown read-only: Likelihood Levels, Impact Levels, Request Impact Levels and Risk Response Options (Mitigate, Avoid, Accept, Transfer). The dimensions and thresholds of your risk matrices are configured separately, in Settings, under Risk Matrix and Qualitative Matrix.

By customising these catalogues, you implement a risk management framework that is efficient and aligned with your company's objectives, and you can adapt quickly as requirements change.