🎉 VSEC Test v4.0.1 is now live! Release Notes ↗

Risk Manager

Risk Manager helps you register, score, and close risks across your workspace. Open it from the sidebar (Risk Manager). Every risk is linked to one or more assets from Asset Manager — one of them the primary asset, chosen at creation — and is scored from the evidence attached to it — structured findings from design analysis (Design), security testing (Test), and vulnerability monitoring (Monitor). Owner assignment, triage workflows, AI context curation, and PDF report export are available for all risk types.

Typical flow: create a risk with New Risk, then Accept it from Triage to move it to Open. Click any risk row to open a preview drawer, then Open details (or right-click → Open risk details) to reach Risk Details for status and ownership; use the Context tab for AI-curated understanding and one-click suggested actions; check the Related tab for auto-derived related risks. Archive hides a risk from the default view without deleting it; Restore brings it back. Archive works from any workflow state, not just Triage.

At a glance

  1. Create your assets in Asset Manager first: every risk requires at least one asset.
  2. Use New RiskCreate Risk to add a risk; it opens in Triage. Accept to move it to Open, or Archive to set it aside (reversible).
  3. Click any risk row to open its preview drawer, then Open details to reach Risk Details. The Risk tab holds status, scoring, and the evidence model; Related shows auto-derived risk relationships; Context shows the AI understanding and suggested actions; Activity is the change log.
  4. Right-click any row in the list for quick actions — change status or priority, assign, attach assets, archive or restore, and permanently delete archived risks.
  5. Click Edit (top right on Risk Details) to open the Edit risk dialog — change the Heading, Priority, or Status, then Save (or Cancel).

Core Concepts

Risks

A risk is an atomic, evidence-driven finding linked to one or more assets (one of them primary) — created in Triage, accepted into Open, and worked through WIPIn ReviewClosed. Risks can also be archived from any state and restored later. Scoring derives automatically from attached evidence as Inherent and Residual values.

Risk Types

Every risk has one of three origins: Design for TARA threat scenarios, Test for security test results, and Monitor for vulnerability findings. The origin determines the type-specific fields and the kind of evidence the risk carries.

Beacon

Beacon is VSEC’s repository-wide overseer. It watches across all active risks and surfaces cross-cutting gaps — incomplete models, stale scores, stalled Clause-8 events, untreated high-residual risks, assets without risk coverage, flagged BOM countries of origin, and matched external signals. A summary card on the Risk Manager landing page links out to the full findings list in VSEC Monitor, where you also configure which rules Beacon runs and triage the external-signals inbox.

Asset Manager

Each risk references one or more assets from Asset Manager, with one designated as the primary asset. At least one asset must exist before you can create a risk.

Libraries

Access the workspace-wide libraries from the Libraries button at the top of the Risk Manager page. Two libraries are available:

Threat Library

Maintains the reusable TARA building blocks for your workspace: Threat Scenarios, Damage Scenarios, Attack Paths, and Attack Steps. Each entity type has a dedicated list and detail page with full create, edit, and delete support. Entities are cross-linked — navigate from a Threat Scenario directly to its related Damage Scenarios and Attack Paths, or from an Attack Path down to its steps.

Control Library

A catalogue of security controls available across your workspace. Each control records its Effort/Cost, Applicable Lifecycle phases, and an optional Training Link. Controls can carry one or more Requirements — structured references (e.g. regulation clauses or DOORS IDs) with an optional deep link to an external system.

Permissions

The Risk Manager page lists every risk your role may see. New Risk requires the createRMRisks permission — without it the button is disabled with an explanatory tooltip. Permanently deleting archived risks requires deleteRMRisks. Your workspace administrator assigns roles and permissions (see VSEC Core for workspace and access management).

Next

Last updated on