Risks
Last checked on
Risks is your risk register: what could go wrong, who keeps an eye on it, how big it is and what you are doing about it. A risk you reduce gets a treatment plan with actions and linked measures.
Why this protects your organisation
Picture the only developer with production access handing in their notice, or a customer losing data because a backup quietly failed. Writing scenarios like these down in advance, each with an owner and a deliberate choice, means you decide what to fix now and what to live with for the time being. ISO 27001 clause 6.1 asks for that decision per risk, and for a record of who accepted whatever risk remains.
Steps
- Open Risks in the Risks group and click the button to create a new risk.
- Fill in Risk and Description, then choose an Owner and the Involved assets.
- Choose the Treatment and the Status, and a Review date if you have one.
- Under Assessment, choose the Inherent likelihood and Inherent impact. Add the Residual likelihood and Residual impact once the treatment is in place.
- If you chose Reduce, add the actions in the Treatment plan section with Create task or Link existing task.
- In the Measures section, use Link measure to connect the measures that make this risk smaller.
- To knowingly leave a risk as it is, use Accept in the list and write a Justification.
The fields
- Owner is the person who keeps an eye on the risk. You choose from the people listed under People.
- Involved assets are the assets the risk concerns, such as a production database or a laptop.
- Treatment is what you do about the risk: Accept, Reduce, Avoid, Transfer or Monitor.
- Inherent likelihood and impact describe the risk as it stands without extra measures. Residual likelihood and impact describe what is left once the treatment is in place. While those are empty, the inherent assessment counts.
What the list shows
The Level (Low, Medium or High) comes from likelihood times impact and the thresholds in your risk assessment method. Without an assessment it reads Not yet assessed. For a risk you are reducing, the Treatment plan column shows how many actions are done. You can filter the list by Status and Treatment.
The treatment plan as a PDF
Download treatment plan at the top of the list gives you a single PDF with the open actions of every risk you are reducing. Useful for a management meeting, or to hand to an auditor.
Trustbird never accepts a risk by itself. A person always does, with a justification that is kept on record.
If it does not work
The likelihood and impact lists are greyed out
No risk assessment method has been established yet. Open Risk assessment method and establish it. After that you can choose likelihood and impact.
I do not see the Accept action on a risk
Accept only appears once the risk has an assessment (likelihood and impact) and has not been accepted yet. If the score is above the acceptance threshold, only the role named in the method may accept it.
I cannot pick Accepted as a status in the form
That is deliberate. A risk can only be accepted through the Accept action, so there is always a record of who accepted it and why.
My risk has no Treatment plan section
A treatment plan only belongs to a risk whose treatment is Reduce. Choose Reduce and save the risk.
Screens this is about
- Risks