Risk Manager
Risk Manager helps you register, score, and close risks across your workspace. Open it from the sidebar (Risk Manager). Every risk is linked to one or more assets from Asset Manager — one of them the primary asset, chosen at creation — and is scored from the evidence attached to it — structured findings from design analysis (Design), security testing (Test), and vulnerability monitoring (Monitor). Owner assignment, triage workflows, AI context curation, and PDF report export are available for all risk types.
At a glance
- Create your assets in Asset Manager first: every risk requires at least one asset.
- Use New Risk → Create Risk to add a risk; it opens in Triage. Accept to move it to Open, or Archive to set it aside (reversible).
- Click any risk row to open its preview drawer, then Open details to reach Risk Details. The Risk tab holds status, scoring, and the evidence model; Related shows auto-derived risk relationships; Context shows the AI understanding and suggested actions; Activity is the change log.
- Right-click any row in the list for quick actions — change status or priority, assign, attach assets, archive or restore, and permanently delete archived risks.
- Click Edit (top right on Risk Details) to open the Edit risk dialog — change the Heading, Priority, or Status, then Save (or Cancel).
Core Concepts
Risks
A risk is an atomic, evidence-driven finding linked to one or more assets (one of them primary) — created in Triage, accepted into Open, and worked through WIP → In Review → Closed. Risks can also be archived from any state and restored later. Scoring derives automatically from attached evidence as Inherent and Residual values.
Risk Types
Every risk has one of three origins: Design for TARA threat scenarios, Test for security test results, and Monitor for vulnerability findings. The origin determines the type-specific fields and the kind of evidence the risk carries.
Beacon
Beacon is VSEC’s repository-wide overseer. It watches across all active risks and surfaces cross-cutting gaps — incomplete models, stale scores, stalled Clause-8 events, untreated high-residual risks, assets without risk coverage, flagged BOM countries of origin, and matched external signals. A summary card on the Risk Manager landing page links out to the full findings list in VSEC Monitor, where you also configure which rules Beacon runs and triage the external-signals inbox.
Asset Manager
Each risk references one or more assets from Asset Manager, with one designated as the primary asset. At least one asset must exist before you can create a risk.
Libraries
Access the workspace-wide libraries from the Libraries button at the top of the Risk Manager page. Two libraries are available:
Threat Library
Maintains the reusable TARA building blocks for your workspace: Threat Scenarios, Damage Scenarios, Attack Paths, and Attack Steps. Each entity type has a dedicated list and detail page with full create, edit, and delete support. Entities are cross-linked — navigate from a Threat Scenario directly to its related Damage Scenarios and Attack Paths, or from an Attack Path down to its steps.
Control Library
A catalogue of security controls available across your workspace. Each control records its Effort/Cost, Applicable Lifecycle phases, and an optional Training Link. Controls can carry one or more Requirements — structured references (e.g. regulation clauses or DOORS IDs) with an optional deep link to an external system.
Permissions
The Risk Manager page lists every risk your role may see. New Risk requires the createRMRisks permission — without it the button is disabled with an explanatory tooltip. Permanently deleting archived risks requires deleteRMRisks. Your workspace administrator assigns roles and permissions (see VSEC Core for workspace and access management).