Managed Risk


Risk Dashboard

Updated Jan 25, 2024

Review mitigated risks

On a monthly or quarterly basis, review mitigated risks to verify that the risks were resolved as expected.

  1. Sign in to the Risk Dashboard.

  2. In the navigation menu, click Risks.

  3. In the Filters section, in the Status list, select Inactive.

  4. In the Risks table, for Inactive risks that are fixed, change the State to Mitigated.

    See Change the State of Inactive risks that are fixed to Mitigated for more information.

  5. (Optional) Verify that the Mitigated risk is resolved.

    See Verify that a Mitigated risk is resolved for more information.

    Note: Mitigated risks are automatically removed after 90 days.

See Risk States for more information.

Change the State of Inactive risks that are fixed to Mitigated

Note: Before you begin, review mitigated risks.

See Review mitigated risks for more information.

  1. Sign in to the Risk Dashboard.

  2. In the navigation menu, click Risks.

  3. In the Filters section, click Clear Filters, and then configure these settings:

    • State — Add these filters:
      • Open
      • Acknowledged, In-Planning
      • Mitigation/Fix in Progress
      • Fixed, Waiting Validation
      • Unsuccessful Validation
    • Status — Add the Inactive filter.
  4. In the Risks section, review the risks. These are risks that were not detected in the last scan, or that are related to offline assets. If you expect any of these risks to be fixed, change the State to Mitigated.

    See Review inactive risks for more information.

  5. In the Filters section, configure these settings:

    • Status — Add Mitigated and Obsolete, and remove Inactive.
    • Resolved Date Range — Enter a date range to view mitigated risks that occurred after fixes or patches were installed.
  6. In the Risks section, review the risks you updated. Verify that mitigation occurred as expected.

    Tip: View the Status of the risk to determine if it is resolved. The State is user-assigned, so it retains the value it had prior to being confirmed as mitigated, including Unsuccessful Validation.

  7. (Optional) Verify that the Mitigated risk is resolved.

    See Verify that a Mitigated risk is resolved for more information.

Verify that a Mitigated risk is resolved

After you change the status of an inactive IVA risk to Mitigated, you can rescan the asset to confirm that the risk is resolved.

Tip: You can only rescan IVA and Agent risks. You cannot rescan an EVA risk.

Note: Mitigated risks are automatically removed after 90 days.

  1. Sign in to the Risk Dashboard.

  2. Change the State of Inactive risks that are fixed to Mitigated.

    See Change the State of Inactive risks that are fixed to Mitigated for more information.

  3. In the Risks section, make sure the Source and State columns are visible. If needed, click Columns, and then select the Source and State checkboxes to view these columns.

  4. In the Source column, click an IVA or Agent risk.

  5. In the information pane, in the State list, select Fixed, Waiting Validation.

  6. Copy the Scanner ID and Host values. You will use these values later.

  7. Scroll to the bottom of the information pane, and then click Rescan.

    The Rescan Options dialog appears.

  8. Select the Scan Now option.

  9. Click Save.

    The asset scan begins. A full suite of tests are performed, including risk validation. Depending on the type of asset, this can take between 15 minutes and 1.5 hours.

  10. In the navigation menu, click Config > Scanner Config.

  11. In the Scanner Configuration section, for Scanner ID, click Details.

    The Scanner Select dialog appears.

  12. In the Search bar, enter the Scanner ID value, and then click the matching ID in the table.

  13. In the Scanning Queue section, do one of these actions:

    • Click the Status column heading to sort the scan queue by status and view the risks with a Status of Running at the top.
    • In the Search bar, enter the Host value.

    Tip: It can take several minutes for the scan to display active scanning data in the queue. If an asset is not scanned, wait several minutes and then refresh your web browser.