Cyber Security Risk Management (CSRM)

Overview:

Cyber Security Risk Management (CSRM) is a structured process organizations use to identify, assess, mitigate, and monitor cyber threats and vulnerabilities that could impact their assets, operations, or reputation. It integrates cybersecurity into broader enterprise risk management, treating cyber risks like financial or operational ones. CSRM helps prioritize resources, comply with regulations, and build resilience against evolving threats like ransomware, data breaches, and supply chain attacks.

Key Features:
  1. Dashboard
    • Delivers a centralized, real-time view of critical risk metrics and statuses, providing a comprehensive overview of ongoing risks, a concise summary of findings, and a detailed impact breakdown (pending integration into CRAM™). This empowers security teams with the insights needed for swift, informed decision-making.

  2. Asset Identification
    • Experience your tailored Cyber Risk Assessment and Management™ (CRAM™), where this module meticulously maps out the assets requiring safeguarding, establishing a robust foundation for risk assessment by laying the essential groundwork for your CRAM™ building blocks.

  3. Asset Inventory
    • Maintains a comprehensive, up-to-date catalog of all assets, including hardware, software, and data. It tracks ownership, location, and vulnerabilities, ensuring nothing is overlooked during risk evaluations.
  4. Assessed Asset
    • Focuses on evaluating the security posture of identified assets. This module assesses vulnerabilities, threats, and potential impacts, providing data to prioritize risk mitigation efforts.
  5. Risk Register
    • Serves as a repository for documenting identified risks, including their likelihood, impact, and status. It acts as a single source of truth for tracking and reporting risks across the organization.
  6. Risk Management
    • Enables the development and implementation of strategies to address risks (e.g., avoidance, mitigation, transfer, acceptance). This module supports planning, executing, and monitoring risk treatment plans.
  7. Task Management
    • Assigns, tracks, and manages tasks related to risk mitigation, such as patch updates or employee training. It ensures accountability and timely completion of security actions.
  8. Geo Location
    • Tracks the geographic distribution of assets and risks, identifying location-specific threats (e.g., market cyber resiliency or market vulnerability level). This aids in tailoring security measures to specific areas.
Pre-requisites:
  1. Access to CyTech - AQUILA
    • Only users assigned the "Owner" or "Admin" role can access the Log Collector installation resources within the platform.

To navigate to CSRM Module please follow the instructions below:

Step 1: Log in to CyTech - AQUILA. click here --> USDC-CyTech AQUILA

Step 2: Click on AI Security & Governance

HEHE-2 (9).png

Figure 1. Overview

Step 3: Click on Cyber Security Risk Management (CSRM)

image.png

Figure 1.1 Cyber Security Risk Management (CSRM)

Step 4:

image.png

Figure 1.3 Navigation

Cyber Security Risk Management (CSRM): Dashboard

The Dashboard page serves as the central hub for visualizing cybersecurity risk metrics and insights within a Cyber Risk Assessment and Management (CRAM™) system. It provides real-time overviews of risk levels, breakdowns, and trends through interactive widgets, charts, and summaries. This interface appears tailored for security teams to monitor risks, identify issues, and facilitate quick decision-making.

image.png

Figure 2 Cyber Security Risk Management (CSRM) - Dashboard

Vulnerability Level

image.png

Figure 2.1 Cyber Security Risk Management (CSRM) -Dashboard / Market Vulnerability

Impact Level

image.png

Figure 2.2 Cyber Security Risk Management (CSRM) - Dashboard / Market Impact Level

Threat Level

image.png

Figure 2.3 Cyber Security Risk Management (CSRM) - Dashboard / Market Threat Level

Overall Probability Breakdown

Overall Risk

image.png

Figure 2.4 Cyber Security Risk Management (CSRM) - Dashboard / Overall Risk

image.png

Figure 2.4.1 Cyber Security Risk Management (CSRM) - Dashboard / Overall Risk / Risk Assessment

Summary of Findings

summary of findings.png

Figure 2.5 Cyber Security Risk Management (CSRM) - Dashboard / Summary of Findings

image.png

Figure 2.5.1 Cyber Security Risk Management (CSRM) - Dashboard / Summary of Findings / Risk Scenario

image.png

Figure 2.5.2 Cyber Security Risk Management (CSRM) - Dashboard / Summary of Findings / Risk Scenario / Detailed View

Risk Event Scores

image.png

Figure 2.6 Cyber Security Risk Management (CSRM) - Dashboard / Risk Event Scores

Overall Impact Breakdown

image.png

Figure 2.7 Cyber Security Risk Management (CSRM) - Dashboard / Overall Impact Breakdown

image.png

Figure 2.7.1 Cyber Security Risk Management (CSRM) - Dashboard / Overall Impact Breakdown / Overall Impact

image.png

Figure 2.7.2 Cyber Security Risk Management (CSRM) - Dashboard / Overall Impact Breakdown / Risk Tolerance

image.png

Figure 2.7.3 Cyber Security Risk Management (CSRM) - Dashboard / Overall Impact Breakdown / Risk Appetite

CRAM™ Live View

image.png

image.png

Figure 2.8 Cyber Security Risk Management (CSRM) - Dashboard / CRAM™ Live View

________________________________________________________________________________________________________________________________________________

Cyber Security Risk Management (CSRM): Asset Identification

The CRAM™ Building Blocks page serves as an onboarding or configuration interface within the Cyber Risk Assessment and Management (CRAM™) system, designed to collect foundational business information for generating a personalized cybersecurity risk profile. This page emphasizes simplicity in input to demystify cyber complexity, targeting users like CISOs, organizations, or individuals seeking to enhance cyber resiliency. 

For detailed instructions, visit the Cyber Risk Assessment section of the AQUILA Documentation, which provides a comprehensive guide to the CRAM™ Building Blocks.

image.png

Figure 3 Cyber Security Risk Management (CSRM) - Asset Identification

________________________________________________________________________________________________________________________________________________

Cyber Security Risk Management (CSRM): Asset Inventory

The Asset Inventory page is a central management interface within the Cyber Risk Assessment and Management (CRAM™) system, designed to centralize, categorize, and visualize organizational assets for enhanced risk visibility. This interface supports risk managers, IT teams, and security professionals in tracking assets like hardware, software, and data, enabling proactive identification of vulnerabilities and exposures.

image.png

Figure 4 Cyber Security Risk Management (CSRM) - Asset Inventory

Assets by Type

Asset Owner

Assets by Criticality

Search and Filter Section

Table Section

image.png

Figure 4.1 Cyber Security Risk Management (CSRM) - Asset Inventory - Details

Action Buttons

image.png

Figure 4.2 Cyber Security Risk Management (CSRM) - Asset Inventory / Asset Library

image.png

Figure 4.3 Cyber Security Risk Management (CSRM) - Asset Inventory / Asset Library / Asset Identification

________________________________________________________________________________________________________________________________________________

Cyber Security Risk Management (CSRM): Assessed Asset

Designed to facilitate the identification, assessment, and classification of potential risks associated with organizational assets (e.g., hardware equipment).

image.png

Figure 5 Cyber Security Risk Management (CSRM) - Assessed Asset

Search and Filter Section

Action Buttons

image.png

Figure 5.1 Cyber Security Risk Management (CSRM) - Assessed Asset / Risk Assessment

image.png

Figure 5.2 Cyber Security Risk Management (CSRM) - Assessed Asset / Start Risk Identification

________________________________________________________________________________________________________________________________________________

Cyber Security Risk Management (CSRM): Risk Register

  1. Critical Risks - Displays the number of risks that require immediate attention based on asset criticality, sensitivity, and exposure.
  2. Risk Status - Shows how many risks have already been assessed versus those pending assessment.
  3. Risk Distribution by Type - Breakdown of all registered risks categorized by their type: Administrative, Technological, Physical, or Others.
  4. Risk Identified by Month - Tracks the number of risks identified across your organization on a monthly basis.
  5. Risk Logs - Shows the entire logs of the risks
  6. Risk Library - Added Risks can be found in this section.
  7. Add Risks / Risk Identification - Risks can be added in this section to be identified and document.

Test (1).png

Figure 6 Cyber Security Risk Management (CSRM) - Risk Register

Test (3).png

Figure 6.1 Cyber Security Risk Management (CSRM) - Risk Register / Add Risks

Cyber Security Risk Management (CSRM): Risk Management

  1. Risk Response Type - Categorizes risks according to the type of response strategy used. It helps identify trends in how different response types are being utilized and can highlight areas where certain strategies may be more effective
  2. Top Risk Owner - Identify the individuals or teams most frequently responsible for managing risks.

  3. Number of Risk Severity - Shows the count of risks divided by their severity levels. It helps in understanding the distribution of risks and focusing attention on the most severe ones that require immediate attention.

  4. Risk Repository - Shows the risk logs and their details.

Test (9).png

Figure 7 Cyber Security Risk Management (CSRM) - Risk Management


When one of the risks from the risk repository is clicked it will show a pop-up window for further details. 

Test (6).png

Figure 7.1 Cyber Security Risk Management (CSRM) - Risk Management / Risk Repository Details / Comments

In this section it shows risk timelines

Test (7).png

Figure 7.2 Cyber Security Risk Management (CSRM) - Risk Management / Risk Repository Details / Timeline

Shows the files associated by the risks

Test (8).png

Figure 7.3 Cyber Security Risk Management (CSRM) - Risk Management / Risk Repository Details / Files

Clicking the detailed view button opens an in-depth panel that summarizes all relevant information about the identified risk, helping users understand its nature, impact, and current status.

image.png

Figure 7.4 Cyber Security Risk Management (CSRM) - Risk Management / Risk Repository / View Details

Cyber Security Risk Management (CSRM): Task Management

  1. Task Gantt Chart

    This section displays a visual timeline of all active tasks, allowing users to easily track task progress and overlapping schedules.

    • Each row represents an individual task, showing its assignee, start date, and end date.

    • The horizontal bar illustrates the task’s duration within the selected date range.

    • The search bar at the top allows filtering of tasks by name or keyword.

    • Users can scroll horizontally or vertically to view all scheduled items.

  2. Task Table

    This section provides a detailed tabular view of all tasks recorded in the system.
    Each row contains the following fields:

    • Risk ID – References the related risk entry from the risk register.

    • Task ID – Unique identifier for each task.

    • Task Title – The specific name or activity assigned.

    • Risk Owner – The individual responsible for managing the associated risk.

    • Assignee – The user assigned to complete the task.

    • Start Date / End Date – Defines the task timeline.

    • Status – Displays the current progress (e.g., Not Started, In Progress, Completed).

    A search field allows users to quickly locate tasks, and pagination controls appear at the bottom for navigation through large datasets.


  3. Task Overview

    This panel provides summary metrics for all tasks currently in the system.
    It includes the following widgets:

    • Unassigned Tasks – Total number of tasks without an assigned user.

    • New Tasks – Tasks recently created and awaiting action.

    • Tasks Completed – Count of tasks marked as completed.

    • Total Tasks – Total number of tasks across all statuses.

    A Create Task button enables users to add new task entries, while the filter dropdown allows sorting of data by criteria such as due date or priority.

Test (11).png

Figure 8 Cyber Security Risk Management (CSRM) - Task Management

Test (12).png

Figure 8.1 Cyber Security Risk Management (CSRM) - Task Management / Create Task

Cyber Security Risk Management (CSRM): Geo Location

The Geographic Map module provides a visual representation of global market cybersecurity indicators, allowing users to analyze risk exposure, vulnerability, and resiliency by geographic region.

This feature supports data-driven decision-making by correlating regional cybersecurity performance metrics with global threat intelligence.

World Map Visualization

Regional Metrics

Four key indicators are shown for the selected region:

Region Selection and Configuration

Test (13).png

Figure 9 Cyber Security Risk Management (CSRM) - Geographic Location


Revision #22
Created 23 September 2025 07:55:02 by Richmond Abella
Updated 15 April 2026 06:56:53