Project\Risk Treatment

Risk Treatment

 

SUMMARY

safeguards (PILAR and NIST)

security profiles (EVL)

Diagram ; ;Description automatically generated

Diagram ; ;Description automatically generated

 

 

You may control how different security measures (safeguards and profile controls) are used.

For the collection of safeguards in PILAR, you may see them (visible) or not.

·       If not visible, they are completely ignored in interface and in risk mitigation.

Shape ; ;Description automatically generated with medium confidence

 

·       If visible, you may choose whether they are applied to mitigate risk, or not.

A picture containing shape ; ;Description automatically generated

·       If visible and applicable, you may choose how to deal with safeguards that are not evaluated (blank). You may ignore them or use them as if a L0 maturity value were assigned to them.

Graphical user interface, application ; ;Description automatically generated

A picture containing graphical user interface ; ;Description automatically generated

For NIST 800-53 rev.5 collection of safeguards, you have the same options:

A screenshot of a computer ; ;Description automatically generated with medium confidence

 

For security profiles, EVL, you may select whether they are visible o invisible.

·       If invisible, they are ignored.

Graphical user interface, text, application ; ;Description automatically generated

·       If visible, you may choose whether maturity values set for controls are automatically propagated (pushed down) to the mapped safeguards.

A picture containing text ; ;Description automatically generated

·       For some security profiles, if visible, you may choose to apply their controls to mitigate risk. only some EVL are instrumented with the mitigation knowledge.

Graphical user interface, text, application ; ;Description automatically generated

 

Many EVL profiles link controls to safeguards, and users may valuate both in parallel.

Previous version of PILAR used ONLY PILAR collection of safeguards to treat risk and used EVL profiles for compliance. You may fall back to that working mode selecting options like this

·       PILAR: visible + apply

·       NIST SP800-53: invisible

·       *evl*: visible + propagate

 

Graphical user interface, text, application ; ;Description automatically generated

 

Top