App navigation: Risk → Threat The Threat module maintains a catalog of threats that could harm your organization’s assets. Threats are linked to risks via the ATVEC Mapping step in the Risk Register. Screen Layout Navigate to Risk → Threat to open the Threat Inventory screen – a grid-based layout listing all defined threats with...
App navigation: Risk → Asset The Asset module maintains an inventory of all organizational assets that need to be protected – systems, applications, data stores, hardware, and other resources. Assets are the foundation of the ATVEC risk methodology used in the Risk Register. Screen Layout Navigate to Risk → Asset. The Asset Inventory screen shows...
App navigation: Risk → Vulnerability The Vulnerability module tracks security weaknesses identified across your asset inventory – whether discovered by a scanner, manually assessed, or imported from a third-party tool. Vulnerabilities are scored using the industry-standard CVSS scale and linked to risks via the ATVEC methodology. Screen Layout Navigate to Risk → Vulnerability to open...
App navigation: Risk → Control The Control module maintains your organization’s catalog of security and compliance controls – the mitigations, safeguards, and procedures you have in place to manage risk. Controls are reusable and can be linked to multiple risks, policies, and authority document requirements. Screen Layout Navigate to Risk → Control to open the...
App navigation: Risk → Risk Register The Risk Register is the central record of all formally identified and assessed risks in your organization. It uses the ATVEC methodology (Asset-Threat-Vulnerability-Exploit-Control) to build risks from your existing inventories, providing an auditable chain of evidence for every risk score. Screen Layout Navigate to Risk → Risk Register to...