Skip to main content

Risk sources

:::caution Administrators only This page describes a setting reserved for organisation administrators. :::

Risk sources represent the actors or threat origins that can trigger a risk: external attacker, malicious insider, natural disaster, etc. They are used to qualify risks during the risk analysis.

Role of risk sources

Each risk identified in a project is attached to one or more risk sources. This characterisation lets you analyse the origin of threats and adapt the treatment plan accordingly.

The sources configured on this page form the organisation's reference set. They are suggested to analysts when they add a risk source in the Risk sources section of a risk's details.

Risk sources list

The page presents all the organisation's risk sources. A predefined set is provided by default by the platform, which you can keep, enrich or replace.

Three actions are available:

  • Add — enter the name of a new risk source
  • Edit — update the name of an existing source
  • Delete — remove the source from the reference set

The changes are taken into account immediately on all new risks created in the organisation's projects.

tip

Align the risk source reference set with the analysis methodology adopted by your organisation (EBIOS RM, ISO 27005, etc.). A consistent reference set makes it easier to compare analyses from one project to another.