-
Notifications
You must be signed in to change notification settings - Fork 2
Specs M4 Risks ISO27005 Risk
risks.models.iso27005_risk.ISO27005Risk
Detailed analysis of a risk scenario following the ISO 27005 methodology: a triplet (threat, vulnerability, asset) with likelihood and impact assessment.
Represents the detailed analysis of a risk scenario following the ISO 27005 methodology: a triplet (threat, vulnerability, asset) with likelihood and impact assessment.
| Field | Type | Constraints | Description |
|---|---|---|---|
id |
UUID | PK, auto-generated | Unique identifier |
assessment_id |
relation | FK → RiskAssessment, required | Parent assessment (methodology = iso27005) |
threat_id |
relation | FK → Threat, required | Exploiting threat |
vulnerability_id |
relation | FK → Vulnerability, required | Exploited vulnerability |
affected_essential_assets |
relation | M2M → EssentialAsset | Impacted essential assets |
affected_support_assets |
relation | M2M → SupportAsset | Targeted support assets |
threat_likelihood |
integer | required | Threat likelihood (on the scale) |
vulnerability_exposure |
integer | required | Vulnerability exposure level (on the scale) |
combined_likelihood |
integer | computed | Combined likelihood |
impact_confidentiality |
integer | optional | Impact on confidentiality (on the scale) |
impact_integrity |
integer | optional | Impact on integrity |
impact_availability |
integer | optional | Impact on availability |
max_impact |
integer | computed | Maximum impact retained |
risk_level |
integer | computed | Risk level (via matrix) |
existing_controls |
text | optional | Existing controls taken into account |
existing_measures |
relation | M2M → Measure | Formalized existing measures |
risk_id |
relation | FK → Risk, optional | Risk consolidated in the register |
description |
text | optional | Narrative description of the scenario |
created_by |
relation | FK → User | Creator |
created_at |
datetime | auto | Creation date |
updated_at |
datetime | auto | Last modification date |
Note: The ISO 27005 sub-module also includes the entities
Threat(risks.models.threat.Threat) andVulnerability(risks.models.vulnerability.Vulnerability), which are the reference catalogs for, respectively, the threats and the vulnerabilities used in the triplets.
Built from docs/ at v0.36.0. Edits made here are overwritten by the next release : open a pull request against the source instead.
- Administration
- Ask Cairn
- Assets and suppliers
- Compliance
- The dashboard
- Finding your way
- Getting started
- Incidents
- How records move
- Organisational context
- Reports and management review
- Risks
- Trust Center
- Architecture
- Configuration
- Contributing
- The documentation system
- Installation
- Internationalisation
- Operations
- Release process
- Security
- Testing
- Adding an assistant provider
- Adding a dashboard widget
- Adding a domain entity
- Declaring a lifecycle
- Adding an MCP tool
- Adding a REST endpoint
- Adding a report
- Interface conventions
- Dashboard widgets
- Lifecycles
- MCP tools
- MCP tool parameters : Assets
- MCP tool parameters : Compliance
- MCP tool parameters : Governance and context
- MCP tool parameters : General
- MCP tool parameters : Incidents
- MCP tool parameters : Reports and management review
- MCP tool parameters : Risks
- MCP tool parameters : System and administration
- MCP tool parameters : Trust Center
- Management commands
- Models
- Permissions
- REST endpoints
- Environment variables
- MCP server
- REST API
- Assistant module (Ask Cairn)
- Module 0: User Management and Access Control
- Module 1: Context and Organization
- Module 2: Asset Management
- Module 3: Compliance
- Module 4: Risk Management
- Module 4 bis - EBIOS Risk Manager
- Module 5 : Trust Center
- Module 6 : Security Incident Management
- Management review : ISO 27001:2022 compliance (clause 9.3)