Attaching controls to a risk

Step 3 of the Add Risk wizard, and available on any risk afterwards from the Controls tab.

Existing versus planned

Existing control Planned control
Means Operating today Intended, not yet built
Affects The residual score The target score
Leads to Nothing further A treatment plan

Attaching one

  1. Select Add existing control or Add planned control.
  2. Search the library and select the control. Controls already attached are hidden from the list.
  3. Set the per-risk properties described below.
  4. Save.

The per-risk properties

This is the part that trips people up on first use. A control does not have one universal strength — it has a specific effect on this risk.

Property What it means
Target dimension Which dimension the control reduces — usually Impact or Likelihood. A backup reduces impact; a firewall reduces likelihood.
Mitigation coverage % How much of that dimension this control addresses, for this risk.
Local implementation status Whether the control is actually in place for this risk’s scope, which is not always the same as the library status.

The same control can cut 40% off one risk and 10% off another. That is not a modelling compromise — it is how controls behave. Encryption at rest is decisive against a stolen-disk risk and almost irrelevant against an insider with valid credentials.

Removing a control

Detaching a control from a risk removes only the link and its local properties. The control itself stays in the library, and its history on this risk stays in the audit log.