What is Risk Management?
The objective of Risk Management is to identify and assess potential threats to the organization. Risks can be related to company assets. Risk assessments can be generated automatically at scheduled times or event-driven. The users responsible receive a task with information about the activities to be performed. By analyzing risks and risk assessments, the company can assess if action is required. The central objects of risk management are risks and risk assessments. Risk assessments are generated only for risks that are enabled for Risk Management by setting the Risk Management-relevant attribute to true. In addition to the standard functions of ARIS Risk and Compliance that are related to risks, Risk Management provides the following options:
Use risk assessments as basis of the control system.
Evaluate risk assessments according to hierarchy element (application system types, regulations and standards, organization, process, risk category) and impact type.
Identify trends for particular values from Risk Management.
Forecast risk assessments to know which risk assessments are generated or expire in a particular period.
Define thresholds to initiate appropriate measures if exceeded.
Definition of impact types
Definition of extent, frequency, detectability, and trend with their respective weighting.
For detailed information on modeling guidelines, refer to the Modeling Conventions.