Attaching controls to a risk
Attaching controls to a risk
Step 3 of the Add Risk wizard, and available on any risk afterwards from the Controls tab.
Existing versus planned
| Existing control | Planned control | |
|---|---|---|
| Means | Operating today | Intended, not yet built |
| Affects | The residual score | The target score |
| Leads to | Nothing further | A treatment plan |
Attaching one
- Select Add existing control or Add planned control.
- Search the library and select the control. Controls already attached are hidden from the list.
- Set the per-risk properties described below.
- Save.
The per-risk properties
This is the part that trips people up on first use. A control does not have one universal strength — it has a specific effect on this risk.
| Property | What it means |
|---|---|
| Target dimension | Which dimension the control reduces — usually Impact or Likelihood. A backup reduces impact; a firewall reduces likelihood. |
| Mitigation coverage % | How much of that dimension this control addresses, for this risk. |
| Local implementation status | Whether the control is actually in place for this risk’s scope, which is not always the same as the library status. |
The same control can cut 40% off one risk and 10% off another. That is not a modelling compromise — it is how controls behave. Encryption at rest is decisive against a stolen-disk risk and almost irrelevant against an insider with valid credentials.
Removing a control
Detaching a control from a risk removes only the link and its local properties. The control itself stays in the library, and its history on this risk stays in the audit log.