How Risk Identification Works
Each risk entry captures the risk description, the affected systems or domains, a likelihood rating, an impact rating, and a calculated composite risk score. Pre-built risk categories align to the 14 CMMC domains so your assessment covers the full scope of your CUI environment systematically rather than ad hoc.
Risks can be entered manually or surfaced from your open POA&M items. Requirements that are not yet met represent concrete, documented gaps that qualify as organizational risks. Linking POA&M items to risk register entries creates a traceable connection between your compliance gaps and your risk posture, which is exactly the kind of integrated documentation that supports a clean assessment.
Risk Scoring and Periodic Assessment Evidence
The Risk Register's scoring matrix produces a calculated risk level for each entry. High, Medium, or Low. Based on likelihood and impact ratings. The composite score drives prioritization, surfacing which risks require immediate mitigation and which can be accepted or monitored.
Every assessment cycle is dated and preserved in the register history. When an assessor examines RA.L2-3.11.1, the evidence they require is proof that risk assessment happened, that it was documented, and that it occurred more than once. The register's revision history provides exactly that. A timestamped record of each assessment cycle with the risks identified, scores assigned, and mitigations tracked.
What You See Inside
- *Risk entry form capturing description, affected domain, threat source, likelihood (1–5), and impact (1–5)
- *Calculated composite risk score and automatic High/Medium/Low classification
- *Pre-built risk categories organized by CMMC domain for systematic coverage
- *Mitigation strategy field with responsible owner, target date, and status tracking
- *Risk acceptance workflow for risks where mitigation is not feasible. Documented acceptance with rationale
- *Direct link from POA&M items to risk register entries. Compliance gaps reflected as formal risks
- *Dated assessment cycles with full history. Each review cycle timestamped and preserved
- *Open risk count displayed on the Assessment Summary dashboard with link to register
- *Risk register section included in SSP Export. Assessors receive the full register as part of the System Security Plan
Practices Satisfied
| Practice ID | Description |
|---|---|
| RA.L2-3.11.1 | Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. |
| RA.L2-3.11.2 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. |
| RA.L2-3.11.3 | Remediate vulnerabilities in accordance with risk assessments. |
| CA.L2-3.12.2 | Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. |
What this replaces
- *A risk register document created once during the initial compliance effort and never updated. Common finding, immediately visible to assessors from the revision date
- *Spreadsheet risk registers with no dated assessment history. No way to demonstrate that periodic assessment actually occurred
- *Compliance gaps tracked in the POA&M with no connection to the risk register. Two separate documents that tell inconsistent stories
- *Risk acceptance decisions made verbally with no documentation. Assessors cannot verify accepted risks are intentional rather than overlooked
- *Risk mitigations tracked in a separate project plan with no link back to the formal risk register entry
Related Modules
Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.