Menu

  1. Introduction
    1. Licensing
    2. System Requirements
    3. Setup and Installation
  2. Getting Started
    1. Creating the Database
    2. RM Studio Users/Contacts
    3. Email Configuration
    4. Web Module Setup
    5. Web Module Update
  3. Navigating RM Studio
    1. Main Menu
      1. Save Function
      2. Import External Data
        1. Import Assets
      3. Clear User Cache
      4. Security
      5. Properties
      6. Languages
      7. Registration
      8. User Manual
      9. Manage Checkouts
      10. About
      11. Application Style
    2. Navigation Tree
    3. Tabs
    4. The Grid
    5. Context & Flow
  4. Common Entities
    1. Business Entities
      1. Asset Details - Basic Information tab
      2. Asset Details - Risks tab
      3. Asset Details - Categories tab
      4. Asset Details - Business Entities tab
    2. Contacts
    3. Teams
    4. Categories
    5. Assets
    6. Threats
    7. Standards/Controls
      1. How to: Standards, Regulations, Controls
      2. Standards Implementation Comparison
    8. Documents
  5. Gap Analysis
    1. How to: Gap Analysis
    2. Reporting
  6. Risk Assessment
    1. How to: Risk Assessment
      1. Working with Assets
      2. Evaluation Values
      3. Evaluating Risks
      4. Various Definitions
      5. Risk Assessment Reporting
    2. Evaluation Templates
    3. Risk Owner Web Solution
  7. Web Module
    1. Dashboard
    2. My Tasks
    3. Reports
    4. Standards/Regulations
    5. Documents
    6. Incidents
    7. Risk Owner Web Solution
  8. Control Maturity and Effectiveness Assessment
    1. Control Assessment Templates
    2. Reporting
  9. Risk Treatment
    1. How to: Risk Treatment
      1. Risk Treatment Templates
      2. Risk Criteria
      3. Asset Level
      4. Controls Tab
      5. Scheduling a Future Control
      6. Future Controls Tab
      7. Overview
      8. Reload Assets, Threats and Controls
    2. Risk Treatment Reports
  10. STPA
    1. Intro to Models, Diagrams, Analyses
    2. STPA Projects
    3. Models and Diagrams
      1. How to: Create HCS Models
      2. How to: Create HCS Diagram
        1. Diagram Elements
    4. Performing the Analysis
      1. Setting up the Analysis
      2. System Level Hazards and Losses
      3. Step 1
    5. Reporting
  11. Business Continuity Management Module
    1. Organization
      1. New Organization
      2. Stakeholders
      3. Resources/Processes
        1. Impact Analysis
        2. Requirements
    2. Incident Response/Recovery
      1. Associated Threats
      2. Plans
        1. Steps
      3. Maintenance
        1. Test plans
        2. Test Results
    3. Templates
    4. Maintenance
    5. Reports BCM
  12. Database Settings
    1. Database Upgrade
    2. Add Existing
    3. Remove
    4. Migrate
    5. Backup
    6. Restore
  13. Glossary
  14. Calculations

4.5.Assets

After inputting your Business Entities and importing the necessary Contacts, another key piece of data you input into RM Studio is the Asset Registry. Assets are anything that has value, tangible or intangible items that bring value to the organization. An Asset can be as general as “Headquarters Building” or as specific as “HP Server, XpV_2831”.

In RM Studio you define your own assets, but remember to only include assets within the scope of your risk management projects. In the Risk Assessment the Assets are selected from the Asset Registry and the Risks are applied based on the predetermined mapping of the Threats to Asset Categories. When you create a new asset you must select the Asset Categories for the asset establish the link to the default threats (you can import new threats or edit the IT threat library and the mapping to Categories, as you need).

The release of v5.4 provides a new way to organize the Assets under specific Business Entities, as well as group according to Asset Categories.

How to: Create a Common Asset

  1. Define your company’s assets within your scoop for the risk assessment under the Common section of the Navigation Tree by double clicking on Assets to open the Asset Browser in work space on to the right.
  2. To add a new Asset you must click on the add button in the Asset List Toolbar.

    Asset Details – Basic Information

  3. Under the Basic Information tab, input a name for the new Asset, keeping in mind to use a unique name for each asset and some assets may be grouped together if risks are the same (e.g. individual computers grouped as workstations all).
  4. Select the Asset Owner from the drop down list that pulls from the Contacts you have added to RM Studio. Description is optional, but it provides a more complete Asset Registry, allowing all RM Studio users and Stakeholders to understand the details of the asset.

    Asset Details – Categories

  5. Next, you select the Categories tab in Asset Details to assign Asset Categories to the new asset. The familiar method in RM Studio for applying Asset Categories to an Asset is to use the button to open the popup with the Categories list.
  6. Select all the Categories that apply to the newly created asset (you can hold ‘Ctrl‘ key and left click all the applicable categories). It is crucial to apply Categories to the new asset, as this step is a prerequisite for connecting Threats to Assets in the Risk Assessment.If you can’t find the appropriate Category or Sub Category, go to Categories under the Common entities and add the new categories or sub-categories you require. Remember to link the new Categories to the relevant threats.Alternatively, you can use the Edit icon to add the Categories to the Asset or to change Categories at a later time if you need to. The function uses check boxes for selecting the Categories and there is no need to hold the ‘Ctrl‘ key when selecting more than one Category for the asset.

  7. When using the Edit function to add Categories, you have the option to ‘Add threats from the Categories to the Assets’ by checking the appropriate box.

    Asset Details – Business Entities

  8. The third tab under Asset Details is for viewing the Business Entities the asset is assigned to. You are unable to edit which BEs the asset belongs to in the tab; this task is done directly under the Business Entities – Assets.
Help Guide Powered by Documentor
Suggest Edit