Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Risk management

Maintain a risk register and model threat-based risk assessments in Probo

View as Markdown

Probo supports two related ways to reason about risk: a risk register for tracked business or security risks, and structured risk assessments for modeling systems, threats, scenarios, and their resulting risks.

A risk record describes a risk, its current state, and the context needed to evaluate it. Risks can be linked to:

  • measures that reduce or monitor the risk;
  • obligations that make treatment necessary;
  • third-party assessments that identify vendor exposure;
  • risk-assessment scenarios that explain how the risk may occur.

Keep the risk statement understandable without relying on a score alone. Record the affected activity or asset, the undesirable event, and the likely consequence.

A risk assessment can contain scopes, nodes, boundaries, processes, threats, and scenarios. Scenarios connect threats to one or more risks and make the assessment’s reasoning reviewable. Scope diagrams can be exported as Mermaid for use in technical review.

Assessments and register entries have separate lifecycles: the assessment documents analysis, while linked risks are the items the organization tracks and treats over time.

Publishing risk records creates a reviewed list without preventing continued program operation. Revisit risks when systems, vendors, controls, or business assumptions change. Use measures and tasks for treatment work instead of placing implementation details only in the risk description.