The Asset Risk Model
The Asset Risk Model is designed to assess the risks associated with your organization's information assets, with a specific focus on InfoSec and Cybersecurity. This model evaluates the impact of losing confidentiality, integrity, or availability of these assets.
The model is designed to calculate risks based on a point scale. Depending on the score, the asset is assigned to a specific risk category. Assets in higher risk categories require specific measures for risk treatment. This structured approach helps you prioritize and address risks effectively.
Configuring an Asset Risk Model
You can create a customized risk model for each of your standards.
- Go to Configure Models, select the desired standard from the list, and choose whether to activate an additive or multiplicative model.
- Click Edit to start the configuration process.
Define Likelihood Levels
- Assign a unique label and threshold value to each probability level. For example, you could define five levels ranging from "Very Low" to "Very High."
- Set the numerical value for each level, representing its weight within the risk model.
Configure Damage Categories
- Select the currency.
- Define thresholds and appropriate labels for each impact category, such as "Minimal" to "Critical."
- Assign a numeric value to each category.
- Save your inputs to proceed.
Activate the Riskmodell
- Click Activate on the top of the page.
- Then click Save.
Once configuration is complete, an overview of the model with all the entered details will be displayed.
Define the asset risk categories
- Click Edit under Configure Models,
- Scroll down to the Asset Risk Categories section and click Set.
- A standard definition ranging from minimal to critical is provided.
- You can retain the default settings or create custom categories.
- It is recommended to keep the default of five categories. This setting can only be changed once.
- Save your configuration.
- A scoring scale appears that weights all previous entries.
- Adjust the thresholds by clicking and dragging to the desired position.
- Define the risk treatment threshold on the lower scale. Risks above this threshold must be addressed.
- Save.
You will now find a list of all active models under Active Model(s).