Appearance
Manage Risks & Mitigations
This guide explains how to identify, score, and manage risks in the Risk Register (/risks).
Step 1: Registering a New Risk
- Navigate to Risk Management > Risk Register (
/risks). - Click + New Risk.
- Fill in the risk details:
- Risk Title: E.g., Unauthorized Access via Stale Privileged Credentials.
- Category: E.g., Cybersecurity, Operational, Third-Party, Regulatory.
- Inherent Severity & Likelihood: Rate on a 1–5 scale based on your organization's risk matrix.
- Risk Owner: Assign the accountable risk manager or domain lead.
- Click Create Risk. The system issues an identifier (e.g.,
RSK-2026-0033).
Step 2: Linking Mitigating Controls & Calculating Residual Risk
- Click on the newly created risk to open its detail drawer.
- In the Mitigating Controls section, click + Add Mitigating Control.
- Select relevant active controls (e.g.,
CTL-2026-0004 Quarterly Privileged Access Review). - OrviQ recalculates the Residual Risk Score based on the effectiveness and coverage of the linked controls.
- Select the Treatment Strategy: Mitigate, Transfer, Avoid, or Accept.