On an accepted demand, expand Risks on this demand and open a risk. The current editor presents the assessment as consecutive sections within the page.

  1. Create the risk. Confirm the new assessment on its parent demand; CSFaaS assigns its RSK reference.
  2. Profile the scenario. Classify the affected security and business areas, threat origin, actors, motivations, vectors and actions.
  3. Assess inherent risk. State the scenario and the assumptions used when excluding mitigating controls.
  4. Assess current risk. Account for the safeguards and limitations that exist today.
  5. Recommend controls. Link appropriate policy or catalog measures and describe additional recommendations.
  6. Assess target risk. Estimate the intended residual exposure under the planned treatment, keeping its assumptions explicit.
  7. Hand off for response. Under an enforced analyst workflow, save the assessment and send the demand for risk response.
  8. Record the decision. Provide each risk's response and justification, establish ownership and complete the required review round.

Keep the records connected

The demand's flow diagram connects it to its risks and remediation plans. Use those links to inspect the relevant record rather than relying on a status summary alone.

Current and target results use configured matrix values. The target is an intended future state until implementation and assessment support it. Completing the demand records the assessment outcome; Risks and Remediation continue to track the resulting work.