Risk Management Procedure | DefectDojo Trust Center

Risk Management Procedure

Policy Statement

This procedure supports the DefectDojo Risk Management Policy by providing practical steps for identifying, assessing, treating, monitoring, and reporting risks.

Scope

Covers organizational and process-level risks affecting DefectDojo, including operational, strategic, compliance, and information security risks.

References

Definitions

Procedure

Organizational Roles

Risk management occurs at two levels:

  1. Organizational level: High-line risks with potential significant impact, recorded in the Risk Register and reviewed by CTO and Board.
  2. Process level: Operational risks managed via existing policies, procedures, and audits.

Identifying Risks

Analysing Risk

Table 1: Likelihood of Risk Occurring

Level Description Probability
1 Rare Occurs only in exceptional circumstances; known elsewhere once every 5+ years <5%
2 Unlikely Could occur at some time; once every 5 years 5–30%
3 Possible Might occur at some time; once every 3 years 30–60%
4 Likely Will probably occur; once during the year 60–90%
5 Almost Certain Expected to occur frequently during the year >90–100%

Table 2: Risk Level Determination

Consequence → / Likelihood ↓ Insignificant Minor Moderate Major Critical
Rare Low Low Low Medium Medium
Unlikely Low Low Medium Medium High
Possible Low Medium Medium High High
Likely Medium Medium High High Very High
Almost Certain Medium High High Very High Very High

Questions to Guide Risk Management

  1. Are assumptions about environment, technology, and resources valid?
  2. What risks arise from implementing or not implementing the strategy?
  3. Are the risk solutions effective and cost-efficient?
  4. Are management and accounting controls adequate?
  5. Do solutions comply with legal, ethical, and organizational requirements?
  6. Can improvements be made?

Evaluating Risks

Managing Risks

Options include:

Assessing Treatment Options:

Monitoring, Reviewing, and Reporting Risks

Methods of Review:

Communication of Risk

Disaster Management and Business Continuity

Supporting Documents

Review

This procedure is reviewed annually or as needed to ensure relevance and effectiveness.