Risk Management
This section contains two workstreams: GAP Analys and Risk Catalog.
Use GAP Analys to evaluate maturity and compliance against frameworks such as CIS Security Controls, Microsoft Zero Trust, and ISO 27001 for NIS2.
Use Risk Catalog to run the operational risk process from setup and gathering to consolidation, assessment, and finalization.
Recommended flow Start with GAP Analys for current-state insight, then continue in Risk Catalog to collect, assess, and finalize risks.