Edit and release a risk analysis
How to change the method framework of an existing risk analysis – events, damage items with their criteria and risk levels – and then release it. The article also covers the functions available in the “Actions” menu of the detail view.
The method framework of a risk analysis defines how your ISMS measures risk: which events are assessed, which damage items and criteria sit behind them, and from which score a risk level is reached. This article shows how to change that framework, release the risk analysis and use the further actions in the detail view.
Prerequisites
- You have the “Edit” permission for risk analyses.
- The risk analysis has the status “New” or “In progress” – otherwise you additionally need permission to edit released documents.
- Releasing requires the corresponding release permission; without it, the “Released” option is displayed as disabled.
Edit the method framework
- Open the detail view of the risk analysis and click “Edit” at the top right. The edit form opens as a side panel titled “Risk analyses” with the “Contents” tab.
- In the “General” section, maintain the master data: “Designation”, “Status”, “Document ID” and “Description”. Use “Type of link” and “Linked to” to define the assessment object, for example a data processing system or a technical and organizational measure.
- In the “Association” section, define which organisations may use the risk analysis, or select “All organisations”.
- In the “Events” section, click “New” to add an event. In the “New event” panel, maintain “Designation”, “Description” and, via “Select type”, the assessment type “Risk matrix”, “Rating”, “Yes / No” or “Yes / No / Maybe”. Confirm with “Apply”. The action menu in each row also offers “Add”, “Duplicate” and “Delete”; you change the order using the drag handle icon.
- Maintain the damage items in the “Damage assessment” section. Within a damage item, use “New” in the “Criteria” section to choose either “Add a criterion” or “Add a criterion for each event”, then select the matching event under “Event”.
- In the “Risk levels” section, click “New” and define each level with “Designation”, “Description” and “Threshold value”. preeco calculates the selectable threshold values automatically from the maximum achievable assessment value.
- Click “Save” at the bottom. You are returned to the detail view and see the confirmation “The risk analysis was successfully updated.”
Release the risk analysis
- Click “Preview” at the top right and check the rendered version as a final control. Close the preview using the X at the top right.
- As long as the status is “New” or “In progress”, a green “Release” button appears at the top right. Clicking it moves the risk analysis to the status “Released”, after which it can be filled in via “Answer”.
- Alternatively, set the status to “Released” in the edit form using the “Status” selection menu.
- On release, preeco automatically creates a new revision. It is visible in the “Revisions” tab and evidences to an audit which method framework was used for assessments at which point in time.
Further actions
Click “Actions” at the top right of the detail view to reach additional functions:
- “Change affiliation” – adjusts only the organisational assignment, separately from the remaining content.
- “Watch” – adds you as an observer so that you are notified about changes.
- “Archive” – moves an already released risk analysis to the status “Archived”, for example after the assessed system has been decommissioned.
- “Download as PDF” or “Download as DOCX” – exports the risk analysis with all contents as a file.
- “Duplicate” – creates a copy as a new draft, ideal for similar assessment objects that share the same method framework.
- “Delete” – permanently removes the risk analysis after a security prompt.
Two tips from practice: only release a risk analysis once the method framework has been agreed within the team – later methodological changes regularly raise the question of whether answers already given are still valid. And if you remove an event, all criteria referring to it are removed with it, so check beforehand whether the associated damage items can still be assessed against the remaining events.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.