Skip to main content

FAQ

This frequently asked questions list gathers the most common queries about the e-Analyze Risk platform, organised by topic. Click a question to display the answer.

Getting started

I just created my account but I cannot see any project.

You are probably not yet attached to an organisation. Contact your administrator so they can add you. As long as you do not have an organisation, you cannot access any feature of the platform.

I log in but I land on a "No account" page.

Your Keycloak identity exists but no e-Analyze Risk account is associated with it. Contact your administrator so they can create your profile.

How do I change the interface language?

Click your profile at the top right → My account. There you can choose French or English.

How do I switch the interface to dark mode?

From My account, the Theme field lets you choose between Light, Dark and Automatic (follows your system preferences).

Projects

In what order should I complete the workflow steps?

Qualification → Risk analysis → Architecture review. Qualification must be completed before launching the risk analysis, because the latter relies directly on the assets, processes and security needs defined during qualification.

Can I modify a project's information after its creation?

Yes, from the project's details page, an edit button lets you change the name, description, lifecycle, dependency type and language at any time.

Can I assign several measure catalogues to the same project?

Yes. From the project's details page, click Measure catalogues and assign as many catalogues as needed. When generating remediation measures, the AI will draw from all the assigned catalogues.

What is the project lifecycle for?

It indicates the project's status within your organisation (New project, Improvement, Migration, Production, Legacy). It is used to filter projects from the list and can guide the AI generations.

Pre-qualification

What happens if I have not attached any assets during pre-qualification?

The AI will have less context to generate feared events and risks. The results will be less precise and less relevant. It is strongly recommended to enter at least the key assets before launching the generation.

Can I answer some questions of the questionnaire manually and let the AI answer the others?

The two modes (automatic and manual) are not mutually exclusive: you can launch the automatic completion, then come back and manually modify the answers that do not seem appropriate.

Can I regenerate only the Availability AICT level without recalculating everything?

Yes. On each Generate button of the summary, click the magic wand and indicate what you want to recalculate (e.g.: "recalculate only Availability"). Generation will be targeted on that single criterion.

How do I view a previous version of a generated summary?

Click the history icon next to the Generate button. You will find all the previous versions of the generation for that field.

What are the documents imported in the scoping cards used for?

They are used by the AI as context during all subsequent generations: automatic questionnaire, AICT summary, feared events, risks and measures. The more complete the documents, the more relevant the generations.

Risk analysis

What is the difference between Standard, Concise and Detailed modes?

These modes control the depth and volume of generations. Concise produces fewer elements with short descriptions. Standard is balanced (default value). Detailed generates a maximum of elements with long, in-depth descriptions. You can also fine-tune these settings via the Advanced settings.

Can I modify a feared event, a risk or a measure generated by the AI?

Yes, all generated data is fully editable. You can modify the description, AICT criteria, levels, treatments, etc. You can also delete some or add some manually.

Can a risk be associated with several feared events?

No. In e-Analyze Risk, each risk is associated with a single feared event. However, a remediation measure can be linked to several risks.

How does the risk matrix work?

It represents risks along two axes: probability and impact. Three views are available: raw (without measures), current (with the measures according to their implementation status) and target (once all measures are implemented). Clicking a cell lists the risks corresponding to that level.

What is the difference between "Reduce", "Avoid", "Accept" and "Transfer"?

These are the four risk treatment modes.

  • Reduce: put in place measures to lower the probability or impact.
  • Avoid: remove the source of the risk by modifying or abandoning the activity concerned.
  • Accept: explicitly decide to take on the residual risk, with monitoring conditions.
  • Transfer: pass the risk to a third party (insurance, subcontracting, etc.).
What are the probability and impact reduction rates on measures for?

They allow the residual risk to be calculated after applying a measure. For example, a measure with −30 % probability and −20 % impact will reposition the risk on the current matrix, letting you visualise the concrete effect of the planned measures.

How do I export a report?

From the Reports tab of your project, several formats are available (Word, Excel). You can export the risk register, the remediation plan and the analysis summaries.

Assets

What is the difference between an asset and a process?

An asset is an element of the IS that has value for the organisation (server, database, application, etc.). A process is a business activity that uses these assets (order processing, user authentication, etc.). Both are linked to feared events during the risk analysis.

Are assets generated by the AI during pre-qualification added to the organisation's catalogue?

Yes. Automatically generated assets are proposed for validation and, once confirmed, integrate the organisation's catalogue. They will then be reusable in other projects.

Agents

What is a Security Review and when should I use it?

A Security Review is a security report generated by the AI that assesses whether the use of a software solution (SaaS, cloud, desktop, library) is acceptable from a security standpoint. It is particularly useful before integrating a new tool into your IS.

How long does a Security Review generation take?

Generation is asynchronous: you can leave the page and come back to consult the result later from the Security Review history.

Can I generate a Security Review in a language other than French?

Yes. At the time of generation, you can choose the language of the report (French or English).

Settings

Do my scale settings apply to all projects of the organisation?

Yes. The scales (impacts, probability, AICT) are defined at the organisation level and apply to all projects. Any modification is immediately taken into account by new AI generations.

Can I create my own measure catalogue?

Yes. From Settings → Cyber Strategy → Measure frameworks, you can create a custom catalogue by entering its title, reference, description and measures (manual entry). The three default MITRE ATT&CK catalogues cannot be modified.

I cannot see the Settings page in the menu.

Access to the settings is reserved for organisation administrators. Contact your administrator to obtain the necessary rights.

Can the default generation settings be adjusted project by project?

Yes. The values defined in Settings → Generation apply by default to all new projects, but they can be overridden at the level of each individual analysis via the Settings button of the risk analysis.

tip

You cannot find the answer to your question here? Consult the Glossary to clarify a term or go to the matching page in the documentation.