Skip to content

Risk Library

Clarion comes with a curated library of 110+ pre-built risks covering 17 security categories. Each risk includes a description, business impact, suggested scores, and recommended compliance control mappings — so you can get your risk registry up and running quickly.

Categories

The library covers these security domains:

CategoryNumber of Risks
Access Control12
Identity & Authentication10
Network Security10
System Controls10
Cryptographic Controls8
Data Protection8
System Integration8
Business Continuity6
Audit & Logging6
Policy Management6
Security Assessment5
Configuration Management5
Personnel Security5
Incident Response3
Asset Management3
System Development3
Risk Assessment2

Adding Risks from the Library

Adding a Single Risk

  1. Go to Risk Management and click + Add Risk
  2. Select the From Library tab — you'll see all available risks as searchable cards
  3. Use the search bar to find risks by keyword (e.g., "ransomware", "phishing", "encryption")
  4. Use the category filter to narrow results by category
  5. Click a card to select it — the form fills in automatically with:
    • Title, description, and impact description
    • Category
    • Suggested likelihood and impact scores
    • Suggested treatment strategy
  6. Compliance controls are linked automatically with default reduction weights
  7. Review and adjust any fields, set an owner and due date, then click Create Risk

Bulk Import

You can import multiple risks from the library at once — each risk is created with all the pre-built details and compliance control links already in place.

First-Time Setup

When you're getting started, use bulk import to quickly populate your risk registry. Filter by category to focus on the areas most relevant to your organization.

What's Included in Each Library Risk

Every pre-built risk comes with:

FieldWhat It Contains
TitleA clear, threat-based name for the risk
DescriptionA 2–3 sentence scenario explaining the threat
Impact DescriptionThe business consequences if the risk materializes
CategoryOne of the 17 security categories
Suggested LikelihoodA recommended score (1–5) based on industry benchmarks
Suggested ImpactA recommended score (1–5) based on industry benchmarks
Suggested TreatmentA default strategy (usually Mitigate, Accept, or Transfer)
Linked ControlsCompliance controls that are automatically mapped when you create the risk

Creating Custom Risks

Not every risk fits a template. Use the Custom tab to build a risk from scratch:

  1. Click + Add Risk and select the Custom tab
  2. Fill in all the fields manually — title, description, category, scores, etc.
  3. The risk starts in Identified status (since there are no pre-filled scores from the library)
  4. Open the risk detail page — the system will recommend relevant controls based on the category you chose

Smart Recommendations

When you create a custom risk, you don't need to know which controls to link. Clarion automatically suggests controls that match your risk's category. For example, an "Access Control" risk will show all available access-related controls. Just click + next to each one to add it.

How Risks and Controls Are Connected

Automatic Linking

  • Library risks — Controls are linked automatically when you create a risk from the library. Each library risk comes with pre-mapped controls.
  • Custom risks — The system recommends controls based on the risk category. You choose which ones to add with a single click.

From a Risk

On any risk's detail page, you'll see two sections:

Mapped Controls shows controls already linked to this risk:

  • Each linked compliance control and its name
  • Whether the control is currently passing, failing, or not yet tested
  • The reduction weights (how much it reduces likelihood and impact)
  • Whether the control is currently effective

Recommended Controls shows controls you might want to add:

  • Based on the risk's category (e.g., "Access Control" risks see access-related controls)
  • Excludes controls already linked to this risk
  • Click + to add a control instantly with default reduction weights

From a Control

On any compliance control's detail page, the Linked Risks section shows you:

  • All risks connected to this control
  • Each risk's title, category, and inherent score
  • A clickable link to jump to the risk detail page

This two-way view helps you answer an important question: "If this control fails, which risks are affected?"

Clarion Security Observability Platform