The Risk Analysis module enables the systematic assessment of identified risks and determination of their levels according to the organisation’s methodology. WebArat allows organisations to define their own categories, values, parameters and calculation methods so that the analysis reflects the requirements of the organisation and the specific area being assessed.
Risk analysis can be performed manually, semi-automatically or automatically using information and relationships from other WebArat modules. The organisation can define its acceptable risk level and, based on the results, decide whether and how individual risks should be treated.
The results of the analysis are linked to the risk treatment plan and security controls. WebArat therefore enables risks to be monitored in a broader context, their development to be evaluated and risk treatment activities to be systematically managed through risk reduction, risk transfer, risk avoidance or risk acceptance.