Documentation
Risk Management
Identify, assess, and manage cybersecurity risks to protect your business
Why Do I Need Risk Management?
Think of risk management like having insurance for your car - except for your business technology:
- Prevent Problems: Spot potential issues before they become expensive disasters
- Make Smart Decisions: Know which security measures are most important to invest in
- Sleep Better: Have plans ready for when things go wrong
- Save Money: Prevent costly data breaches and system downtime
- Meet Requirements: Many compliance frameworks require documented risk management
What You'll Learn
What is Risk Management?
Risk management is about identifying what could go wrong with your technology and business, then creating plans to prevent or handle those problems.
Real-World Example
Imagine your main computer server crashes and you lose all customer data. Risk management helps you:
1. Identify this as a possible threat
2. Assess how likely it is and how much damage it would cause
3. Create backups and recovery plans to prevent or minimize the impact
Key Features
Risk Identification
Find potential threats to your business - from cyber attacks to equipment failures to human errors.
Risk Assessment
Rate how likely each risk is and how much damage it could cause to prioritize your efforts.
Treatment Planning
Create action plans to prevent, reduce, or prepare for each identified risk.
Progress Tracking
Monitor how well your risk controls are working and update plans as needed.
Getting Started
Quick Start Guide
- Start Simple: Begin with obvious risks like "What if our internet goes down?"
- Use Templates: AMARA provides common risk scenarios to get you started
- Involve Your Team: Different people see different risks - get input from various departments
- Focus on High Impact: Prioritize risks that would seriously hurt your business
- Create Action Plans: For each major risk, decide what you'll do about it
Common Use Cases
Technology Failures
Server crashes, software bugs, hardware failures, internet outages
Cyber Attacks
Hackers, malware, phishing emails, ransomware, data breaches
Human Errors
Accidentally deleting files, falling for scams, misconfiguring systems
Compliance Issues
Failing to meet legal requirements, losing certifications, regulatory fines
Best Practices
Pro Tips
- Review Regularly: Risks change as your business grows - update your assessments quarterly
- Test Your Plans: Regularly check that your backup systems and response plans actually work
- Document Everything: Write down your risks and plans so everyone knows what to do
- Start Small: Begin with the most obvious and serious risks, then expand over time
- Get Executive Support: Make sure leadership understands and supports risk management efforts
Jira Integration & Automated Remediation
Risk Management connects directly to Jira for tracking remediation work. When you create a Jira ticket from a risk record, amara automatically:
- Posts the ticket to your Jira project with risk details pre-filled
- Creates a treatment plan at 20% progress
- Monitors the ticket via 5-minute polling
- Auto-progresses the treatment when Jira resolves (capped at 90%)
- Notifies you via bell notification for the final human sign-off
- Cascades to "Mitigated" when you click Validate & Close
Human Gate
Treatment auto-progress is hard-capped at 90%. Only a human can validate to 100% and close the risk. This ensures auditability — a resolved Jira ticket is evidence, not automatic proof.
Integration with Other Modules
Risk Management connects to Asset Management (assets available for risk scoring), all 5 assessment modules (compliance gaps create risk entries), Jira (automated remediation chain), and Confluence (link runbooks or remediation plans to risk records).