CSFaaS structures risk work around a Demand, the Risks assessed within it and any associated Remediation plans. It provides places to record context, evidence, ratings and decisions. The organisation remains responsible for selecting its methodology, criteria and decision authority.
Combine assessment perspectives
The workflow supports threat-oriented analysis through threat profiling, asset and impact analysis through business context and linked systems, and vulnerability-oriented analysis through weaknesses and controls. Use the perspectives together where useful, while documenting the scope and limits of the assessment.
Related-risk links help reviewers consider dependencies and previous assessments. They do not automatically calculate correlations, a combined probability distribution or total financial exposure. Using the workflow also does not by itself demonstrate conformity with a NIST or ISO publication.
Gather and frame the information
Create a demand with a clear title and requester, then document the business purpose and relevant classifications. Depending on the scope, these may include region, country, business unit, functional domain, data classification, project phase and the impact of a proposed change.
Explain Context, As is, To be, In scope and Out of scope. Distinguish the environment operating today from proposed changes and boundaries that the assessment will not cover.
Link the relevant business goals and objectives, business drivers for security, policies, systems, third parties and related risks. These associations explain why the assessment matters and help reviewers locate the supporting records.
Describe the risk scenarios
Add a risk assessment to the demand and give it a specific title and statement. Use the available profile fields to describe the security domain, business attributes, category, threat source, actor, motivation, vector and other relevant characteristics.
Taxonomy supports comparison and searching; it does not replace the scenario narrative. Explain what could happen, which weakness or condition makes it possible and what consequence matters to the organisation.
Assess inherent, current and target conditions
For each assessment stage, document the statement and the relevant strengths, weaknesses, opportunities and threats. Apply the workspace's configured matrices and explain the ratings.
| Stage | Assessment basis |
|---|---|
| Inherent | The defined scenario before taking the specified controls into account. |
| Current | The controls and conditions operating now. |
| Target | The expected condition after the proposed response or improvements. |
The threat and vulnerability selection yields the configured likelihood reading; likelihood and impact then determine exposure. Use the actual matrix definitions rather than assuming a universal multiplication rule between every input or a standard set of labels.
Recommend relevant controls and explain how they address the identified weaknesses. A control recommendation and a target rating are plans until implementation and effectiveness have been reviewed.
Decide and follow up
Record a response—Mitigate, Accept, Avoid or Transfer—with its justification. Follow the workspace's direct or enforced demand workflow, including the response and validation steps it requires.
Use remediation plans for eligible mitigation work, assigning responsibilities and dates. Review the resulting risks in Risks and the plans in Remediation. Response selection, risk closure, plan completion and demand closure are distinct actions; one should not be assumed to complete the others.
Reassess when circumstances or evidence change. Keep the decision history and review responsibilities clear enough for another authorized person to understand what was accepted, what remains open and what must happen next.