You can find these options in the Risk Settings menu.
What You Can Do Here
Review the organization’s CRQ readiness using the CRQ Readiness Check.
Launch and complete the Readiness Self-Assessment covering Inventory Coverage, Entity Categorization and Tagging, and Exposure Assessment Fidelity.
Edit enterprise-level risk valuation using the Edit Enterprise Impact section.
Configure risk impact categories including Incident & Response Costs, Data Recovery & Restoration Costs, Business Interruption Costs, Fines, Legal & Defence Costs, Financial Fraud, Physical Damage Costs, and Indirect Losses.
View and validate predefined assumptions in the Cost Assumptions List.
Review consolidated financial impact estimations in the Impact Details section.
Set organizational impact values using the Set Impact control.
Perform a detailed control maturity evaluation using the Maturity Assessment tool.
Select specific controls such as Entity Management and User Management for evaluation and configuration.
You can also see the walkthrough in this link
Risk Settings
In Risk Settings, you can configure the parameters that will determine the way CRQ calculates impact.
These are the modules you can configure:
CRQ Readiness Check
Impact Settings
Assessment
Other Settings
CRQ Readiness Check
CRQ Readiness Check is a non-binding questionnaire to assess readiness for CRQ. You are required to check if the following has been implemented:
Inventory Coverage: Indicate if enterprise asset, application, and user inventory is sufficiently comprehensive and accurate to enable appropriate coverage for key risk scenarios.
Entity Categorization and Tagging: Indicate if enterprise asset, application, and user inventory has been accurately categorized and assigned sufficient context (tags and roles) to specify key risk scenarios.
Exposure Assessment Fidelity: Indicate if exposure assessment across vulnerabilities, categorizations, and other findings is sufficiently comprehensive, accurate, prioritized, and timely to provide an effective view of the enterprise security posture.
Edit Enterprise Impact
In this section, you can configure the following variables:
Groups
Currency
Industry type
Number of customers
Number of annual working days
Headquarters country
Annual revenue
Number of employees
Enter Firmographics
Incident and Response Costs
Notificant Costs
Credit Monitoring Costs
Card Replacement Costs
Forensic Investigation Costs
Public Relations Cost
Average Employee Training Costs
External Cyber Experts Cost
Data Recovery & Restoration Costs
Ransom Payment Costs
Data Restoration Costs
Business Interruption Costs
Business Downtime Costs
Direct Loss of Funds Costs
Monetary Theft
Fines
PCI Non-Compliance Fine
PHI Non-Compliance Fine
PII Non-Compliance Fine
GDPR Fine
Other Regulatory Fine
Legal & Defence Costs
Legal Guidance & Defence Costs
PCI Consumer Settlement Costs
PHI Consumer Settlement Costs
PII Consumer Settlement Costs
Financial Fraud
Fraud Reimbursement Costs (Customer)
Physical Damage Costs
Endpoint Replacement Costs
Server Replacement Costs
Indirect Costs
Cyber Security Investment Costs
Customer Churn Costs
Cost Categories
Notification cost per customer
Credit monitoring cost per customer
Card replacement cost per customer
Average daily forensic team cost
Average daily external PR team cost
Average security awareness cost
Average daily external cyber team cost
Average daily data restoration team cost
Average daily external legal team cost
Number of days forensics team is required for
Number of days external cyber team is required for
Number of days data restoration team is required for
Number of days legal team is required for
Number of days PR team is required for
Cost per PII record
Average endpoint repair cost
Average server repair cost
Percentage of endpoints affected
Percentage of servers affected
Percentage of customers affected in scenario
Number of days downtime
Percentage of fine
Percentage of customers churn
Perform Control Maturity Assessment
You can set the maturity level for the following controls:
Entity Management
Business Continuity and recovering planning
Data Protection
Exposure Management
Deception Technologies
Endpoint Security
Secure Configuration Management
Compliance
Continuous Monitoring
Identity and Access Management
Incident Response and Prevention
Log Management
Capacity and Performance planning
Human Resource Security
Cyber Insurance
Third Party Management
Project and resource management
Risk Management
Secure Engineering Architecture
Network Security
DDoS protection
Change Management
Email gateway security
Privileged Account Management
AI Risk Management
The possible Maturity Levels are:
Not implemented
Initial (Ad hoc)
Repeatable (Managed)
Defined (Standardized)
Managed (Monitored & Measurable)
Optimized (Continuous Improvement)
Set Risk Appetite
Coming soon