This new feature will add a Change Manager to the tool so changes to the risk assessment can be identified and handled in a structured way. The Change Manager can e.g. be used when updating the risk assessment, adding new products or if you want to compare the risk assessment to a historic date. The Change Manager can also be used to see changes made by another user.
Key features
- The Change Manager will list all changes to the Risk Assessment in a side panel
- While the Change Manager is active all current changes are highlighted in the application
- Click on items in the list to navigate and track your progress using the check boxes
- The Change Manager has a save and load functionality so that lists and progress can be stored and loaded
- Filters are used to help focus on certain change types
Use Case – Updating an existing risk assessment
When updating an existing Risk Assessment with a new data model the Change Manager will help you to assess changes to threats and risks following the standard risk assessment process steps.
- Go to settings and select the latest data model (e.g. 2022:9) which includes the latest version of Acuminors threat and risk analysis. When you save the settings page you will be asked if you want to open the Change Manager. Click “Save and use Change Manager”
- A side panel featuring the Change Manager will now open on the right side of the application. All changes that was triggered are now listed here
- Save the change report so that you can come back later if needed.
- By using the default filters: Inherent Risk Assessment, Control Assessment and Verify Residual Risk it is possible to go through, assess and handle changes following the risk assessment process order
- Start with the Inherent Risk Assessment filter and go through changes to threats. Do the changes you feel are needed and use the check boxes to track progress
- Continue with the Control Assessment filter to secure that added risks are mitigated
- When these two steps are completed you can use the Verify Residual Risk filter to assess changes to residual risks