🎉 VSEC Test v4.3.1 is now live! Release Notes ↗

Risks

A risk is an atomic, evidence-driven finding in your workspace. Risks have one or more assets (one of them primary) and progress through a status lifecycle from intake to closure. Scoring derives from attached evidence as Inherent and Residual values computed from the evidence model. A risk also has an origin (Design, Test, or Monitor) once it has evidence — a new risk with no evidence yet has none.

Risk Lifecycle

All risks start in Triage. From there:

  • Accept moves the risk to Open.
  • Archive hides it from the default list (reversible — see Archived risks).

Once open, risks advance through Open → WIP → In Review → Closed. Archive is available from any state, not just Triage — archiving a risk that is already past Triage moves it out of the active view in one step without changing its lifecycle status.

These are the same status labels shown everywhere — the risks list, the Risk Details page, and PDF reports: Triage, Open, WIP (shown as In Progress), In Review, Closed, and Archived.

In This Section

Last updated on