In RM Studio we offer the user the possibility to manually control reloading of Assets, Threats and Controls when working in Risk Treatments (image 15.10). In an earlier version of RM Studio the option was added to the user to e.g. delete controls from the Risk Treatment, that is to change the threat-control associations in the Risk Treatment level to be more aligned to the user’s need. This means that the user can now e.g. delete controls from either an asset level (from the Management Tab – grouped by an asset) or from global level (from the Controls Tab).
The function of this button is as follows:
- If the list of assets has changed in the Risk Assessment, the new assets and their associated threats from the Risk Assessment get reloaded.
- If the list of threats associated to a particular asset has changed in the Risk Assessment the risks are reloaded into the Risk Treatment.
- If the mitigating controls to risks in the Risk Assessment have changed those controls get reloaded into the Risk Treatment as mitigating controls to that risk.
- If a new control has been added to the Gap or Standard used when creating the Risk Treatment, these new controls are loaded into the Risk Treatment.
- In general the list of controls is reloaded, based on the threat-control library as well as the Standard/Gap that was used.