Associating Threats, Vulnerabilities And Controls With Risks

New risks are more meaningful if they are associated with threats, vulnerabilities, and controls. When your user role has Risk View and Risk Author permissions, you automatically obtain the access rights to update a risk so that threats and vulnerabilities can be associated, related controls can be added or removed, and fields in the Exposure tab can be updated.

To add threats or vulnerabilities to a risk:

  1. In the RiskVision Application application, go to Content > Risks.

  2. Find the desired risk in the tree on the left, open it, and click Edit.The Edit Risk screen.
  3. To associate a threat with this risk, choose it from the Threat drop-down list. Likewise, to associate a vulnerability

    with this risk, make a selection from the Vulnerability drop-down list.

  4. Click Save.

 To relate controls and subcontrols to the new risk: 

  1. In the RiskVision Application application, go to Content > Risks.
  2. Find the desired risk in the tree on the left, open it, and click Edit.
  3. Under Related Controls and Subcontrols, click Add to bring up the Control Selection dialogue box. Find the desired control or subcontrol, select it, and click OK.The Control Selection dialogue box.
  4. In the Risk General Tab, click Save.