IT Risk
The service behind every IT risk
An IT risk is read from the service it threatens: the assets underneath, their lifecycle state, whether recovery has been tested and whether capacity is running out. The programme sits on the same register and methodology as everything else.
- Service dependency view: which assets and processes an IT risk touches
- Lifecycle exposure: assets in maintenance, change pending, suspended or retired
- DR readiness and capacity watch as standing views
- Same scoring model, appetite and escalation as the enterprise programme
In the application · Assure
- Risk register
- Service health
- Dependency view
- Lifecycle exposure
- DR readiness
- Capacity watch
Draft·asset-coordinator creates
Dependencies
Risk that knows what it touches
Risks carry typed links to assets, business services, processes and capabilities, so a risk on a shared platform surfaces on every service that depends on it, and the executive drill-down can walk from the outage to the objective.
- Typed risk relationships, including risk-to-risk
- Links to assets, processes, services and capabilities
- Control links with defined control roles
- Findings raised from risk carry the link back
- PaymentsDomain
- Card acquiringCapability3 risks2 policies
- Merchant settlementService4 controls2 assets
- Daily reconciliationProcess1 risk2 controls1 finding
Every level links out to risks, controls, policies, findings, assessments, and assets
Standing views
Exposure you do not have to go looking for
Lifecycle exposure, DR readiness and capacity watch are computed from the asset register and the risk register together, so the programme's standing questions have standing answers.
- Assets past end-of-support or in change-pending state surfaced against their risks
- Recovery test dates and results on the service
- Indicators with thresholds on the IT programme
- Program comparison and cross-programme monitoring
Privileged accounts without review
KRI · monthly · owner: Security Operations
Framework alignment
Works with your control frameworks
This module shares the platform control library. International standards, sector regulations and your own internal standard are loaded the same way and mapped to one another, wherever you operate.
Solutions by role
Built for your team
See IT risk in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.