Assets, Vendors & Frameworks

How to link an asset to a risk on Mac

You can do this with RiskOS, a risk register for macOS. Name what you are protecting, then say which risks are pointed at it.

A register of risks tells you what could go wrong. A register of assets tells you what would be harmed. Apart, the first reads as a list of worries and the second as an inventory nobody has ranked. Connect them and both questions become answerable: what does this risk threaten, and what is the worst thing hanging over this system?

Note

Linking an asset is context, not scoring. It changes what your register can show you and who it can tell; it does not move a likelihood, an impact or a band.

Assets have their own section. In the sidebar, under Inventory, choose Assets. The list in the middle holds everything you are protecting; the panel on the right shows and edits whichever record is selected. Vendors sits beside it, for the third parties you depend on rather than the things you own.

The link itself is made from the other end. Open a risk and the panel on the right carries a Context section: the assets and vendors that risk touches, each shown with its criticality badge so you can see at a glance whether the thing under threat is peripheral or central. That one section is where a risk stops being abstract.

  1. Open the Assets list

    Choose Inventory ▸ Assets in the sidebar. Every asset you have recorded appears in the list, and the section is searchable, so before you add anything, type a word or two from the name to check the record does not already exist under a slightly different spelling.

  2. Create the asset you are protecting

    Press N to add a record to the section you are in. Give it the name people actually use in conversation, and set its type — a system, a set of data, a facility or a process. Naming it the way the business names it is what stops the same thing being entered twice later.

  3. Set its criticality and owner

    Criticality says how much the organisation depends on this asset, and it is the badge that will appear beside the asset wherever it is linked. The owner is the person who would be called first if it were unavailable. Both are worth a moment's thought now, because they are what makes a linked list readable rather than decorative.

  4. Open the risk that threatens it

    Choose Risks in the sidebar and select the row. Search covers the title, reference, category, owner, detail and tags, so a fragment like ransomware or RSK-0001 will find it. If the risk does not exist yet, press N and write it down before you link anything to it.

  5. Open the Context section

    In the risk panel, open Context. It holds the assets and vendors that risk touches, each with its criticality badge, so one look tells you whether anything of consequence has already been recorded against the risk. Context is the section that answers "what would this actually damage".

  6. Add the asset from Context and it joins the list with its criticality badge beside it. Link what the risk would genuinely reach, not everything nearby: for a ransomware risk that is the file shares and the backup copies, not every laptop in the building.

  7. Add the vendors in the same pass

    Context holds vendors as well as assets, and most real risks involve both — a hosted platform is a vendor, the customer data inside it is an asset, and the outage threatens the two together. Adding them at the same time means the risk reads completely the next time somebody opens it cold.

  8. Return to Inventory ▸ Assets and select the asset you linked. It now shows its worst residual risk — the highest remaining exposure among every risk pointed at it. That figure is the one to quote when somebody asks how well protected a particular system is, because it accounts for the controls you have already recorded.

What an asset record holds

An asset record is deliberately short. Four things you type, one thing RiskOS works out for you. Everything else you might be tempted to put here belongs on the risks themselves, where it can be scored and reviewed.

The fields on an asset record and what each one is for
FieldWhat it holdsWhy it earns its place
NameWhat the thing is called in the businessStops the same asset being recorded twice under two names.
TypeSystem, data, facility or processSeparates what runs from what is stored and what people do.
CriticalityHow much depends on itShows as a badge wherever the asset is linked to a risk.
OwnerWho answers for itGives every linked risk a second name to call on.
Worst residual riskCalculated from the risks linked to itOne number for how exposed this asset is today.

Choosing a criticality honestly

Criticality is about dependence, not about how much attention the asset currently gets. Ask how long the organisation could operate without it, who notices when it stops, and whether anything else can stand in for it. A process nobody has automated is often more critical than the well-loved system beside it.

What belongs in an asset list

Record the things a risk could plausibly be written about: customer data, the platform it lives on, the payroll run, the warehouse, the regulatory reporting process, the backup copies. If you would never write a risk against it, it does not need to be here.

Linking is a two-way statement, and each direction answers a different question.

On the risk side

Context turns a one-line risk into something a reader can picture. "Ransomware encrypts primary file shares" is a sentence; the same risk showing the file shares, the backup copies and the hosting vendor beneath it, each with a criticality badge, is an argument. It is also the quickest way to spot a risk written too broadly: if Context needs nine assets, it is probably three risks.

On the asset side

Each asset shows the worst residual risk among everything linked to it. That is a maximum, not an average, and on purpose: one High risk against a system means the system is exposed, however many Low risks sit beside it. It answers the question owners actually ask, which is never "how many risks are there" but "how safe is my platform".

What linking does not do

It does not change a score. Inherent likelihood and impact are yours to rate, and RiskOS calculates the residual figure from the effectiveness of the controls you link. A high-criticality asset does not raise a rating, and a peripheral one does not lower it. Criticality helps you prioritise among risks that score the same, which happens often on a 5×5 scale.

A worked example

A small register of twelve active risks, with the assets linked in, resolves into something like this. Note how few assets it takes: the same five records carry most of the register.

Five assets, the risks linked to each, and the worst residual risk that results
AssetTypeRisks linkedWorst residual
Primary file sharesDataRSK-0001, RSK-000715 — High
Order fulfilmentProcessRSK-001112 — High
Regulatory reportingProcessRSK-000510 — High
Customer-facing assistantSystemRSK-00069 — Medium
Payroll platformSystemRSK-00038 — Medium

Primary file shares carries 15 because RSK-0007, Backup restoration has never been tested end to end, still sits at a residual of 15 against an inherent of 20. The restore rehearsal that would bring it down is recorded as a control, and it is planned rather than operating, so it reduces nothing yet. The asset's figure moves the moment that changes.

Bringing an existing inventory in

An inventory you have already drawn up does not need retyping. Assets import from CSV with the same mandatory preview every import in RiskOS uses: line by line, what will be created, updated or skipped, any problems, and any columns that were ignored. Nothing is written until you confirm.

A record whose name matches one already in your inventory updates that record rather than adding a second, so a revised list can be brought in again later without leaving duplicates behind. Templates ship with RiskOS, so the column names are never a guessing game. Import the inventory first, then make the links: it is quicker to open twelve risks and add assets than to open sixty assets and hunt for risks.

Troubleshooting

The asset I want to link is not there

It has not been created yet. Assets live in their own section: choose Inventory ▸ Assets, press N, and give the record a name, a type, a criticality and an owner. Then return to the risk and open Context again.

The same system appears twice in my inventory

Two records, two spellings — usually one typed by hand and one brought in by a CSV import. Decide which name the business actually uses, re-link the risks pointing at the other, and keep the survivor. Because an import matches on the entity's name, agreeing the name once stops the pair reappearing later.

An asset's worst residual risk looks too low

The figure reflects the risks linked to that asset, so a low number nearly always means a link is missing rather than that the asset is safe. Open the register, search for the terms that describe the asset, and check each risk's Context section. A risk written about a process often threatens a system nobody thought to add.

Every risk lists almost every asset

Links have stopped carrying information. If a risk genuinely reaches everything, it is written at the wrong altitude: split it into the specific failures you would treat differently. Keep to the assets whose loss or damage is what the risk is about, and the badges start telling you something again.

I linked a critical asset and the score did not move

That is intended. Assets record what is at stake, not how likely or how bad the event is. If you want the rating to change, change the inherent ratings or link a control: only controls that are implemented or operating reduce a residual score, and RiskOS shows its working either way.

Habits that keep the map useful

  • Start from the risks, not the inventory. Work through the register and record each asset as a risk names it. The list that results is the one your risks actually need.
  • Name things once. Agree the business name for each asset and use it everywhere, so the inventory never splits into near-duplicates.
  • Link both ends of a third-party risk. The vendor and the data they hold are different objects, and Context carries both.
  • Re-read criticality once a year. Dependence moves quietly. A process that was manual and marginal last year may now be the only route to a regulatory deadline.
  • Use the asset view for owner conversations. Open the asset, quote its worst residual risk, and talk about the two or three risks behind that number rather than the whole register.
  • Watch for assets with no risks at all. Either nothing threatens them, which is rare, or nobody has looked — and the second is worth an hour.
  • Include the inventory in the record you keep. When you back the register up, the assets, the vendors and every link between them go with it in a single file.

Frequently asked questions

How do I link an asset to a risk?

Open the risk from the Risks section, open the Context section in the panel on the right, and add the asset. It appears in the list with its criticality badge. If the asset does not exist yet, create it first in Inventory ▸ Assets with a name, a type, a criticality and an owner.

What counts as an asset in a risk register?

Anything you are protecting: a system, a set of data, a facility or a process. The working test is whether you would ever write a risk against it. Customer data, the payroll run, the warehouse and the regulatory reporting process all qualify; individual pieces of desk equipment generally do not.

Does linking an asset change the risk score?

No. Likelihood and impact are rated by you, and the residual score is calculated from the effectiveness of the controls linked to the risk. An asset's criticality is context: it helps you choose between two risks that scored the same, and it tells a reader what is at stake, but it never moves a number.

What does an asset's worst residual risk mean?

It is the highest residual score among all the risks linked to that asset — a maximum rather than an average. One High risk means the asset is exposed, however many small risks sit beside it. Because residual scores already account for your operating controls, it reads as how exposed the asset is today.

How many assets should one risk be linked to?

Usually one to three. Link what the risk would genuinely reach, not everything nearby. If a risk needs eight or nine assets to describe it, that is normally a sign it has been written too broadly and would be more useful as two or three separate risks with their own ratings and treatments.

Can I import an asset list I already keep?

Yes. Assets import from CSV with a preview that shows, line by line, what will be created, updated or skipped, along with any problems and any columns that were ignored. A name matching an existing record updates that record instead of adding a duplicate, so a revised list can be brought in again later.

What is the difference between an asset and a vendor?

An asset is something you are protecting; a vendor is a third party you depend on. A risk panel's Context section carries both, because most real risks involve the two together — the supplier who runs a platform, and the customer data inside it. Vendors also hold a relationship owner and a review date of their own.

Does my asset inventory leave my Mac?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. Assets, vendors and the links between them stay with the rest of the register, and go somewhere else only when you export or back them up yourself.