Mitigations
Overview
The Mitigations component is a critical part of the Risk Management module, designed to help organizations plan, implement, and track specific actions to reduce identified security risks. This component provides a structured approach to risk treatment, enabling you to document, assign, and monitor mitigation activities.
Effective risk mitigation is essential for reducing your organization's security exposure and demonstrating due diligence in addressing identified risks. The Mitigations component integrates with the Risks component and other elements of the Risk & Compliance Suite to provide a comprehensive approach to risk management.
Key Features
Mitigation Planning
Task Definition - Create detailed plans for addressing identified risks
Resource Allocation - Assign personnel and resources to mitigation activities
Timeline Management - Set realistic deadlines for implementation
Priority Setting - Determine the relative importance of different mitigation tasks
Mitigation Strategy - Document the approach for reducing risk exposure
Mitigation Assignment
Owner Designation - Assign responsibility for implementing mitigation tasks
Stakeholder Involvement - Identify all parties affected by or contributing to the mitigation
Notification System - Alert relevant personnel about assignments and deadlines
Accountability Tracking - Monitor ownership and responsibility for each task
Escalation Procedures - Address delays or implementation challenges
Mitigation Monitoring
Status Tracking - Monitor the current state of each mitigation task
Progress Updates - Record incremental steps toward implementation
Due Date Management - Track deadlines and identify overdue tasks
Dependency Management - Handle relationships between related mitigation activities
Implementation Evidence - Document proof of completed activities
Mitigation Effectiveness
Effectiveness Assessment - Evaluate whether mitigations have reduced the risk
Testing Procedures - Define and execute tests to verify implementation
Evidence Review - Examine documentation of completed mitigations
Residual Risk Calculation - Determine remaining risk after mitigation
Continuous Improvement - Refine mitigation strategies based on outcomes
Getting Started
Accessing the Mitigations Component
Log in to your AskInfosec account
Navigate to the main dashboard
Select "Risk Management" from the main navigation menu
Click on "Mitigations" in the submenu
You will be directed to the Mitigations dashboard
Mitigations Dashboard
The Mitigations dashboard provides an overview of your organization's risk mitigation activities, including:
Mitigation Summary - Total mitigation tasks by status and priority
Recent Mitigations - Latest mitigation tasks created or updated
Overdue Mitigations - Tasks past their implementation deadline
Mitigation by Owner - Tasks grouped by responsible individuals
Mitigation Trends - Patterns in task creation and completion
Managing Mitigations
Creating a New Mitigation Task
To define steps for addressing an identified risk:
From the Mitigations dashboard, click the "Add Mitigation Task" button
Enter basic task information:
Task Name
Description
Priority (High, Medium, Low)
Related Risk (if applicable)
Assigned To
Due Date
Add detailed information:
Implementation steps
Success criteria
Required resources
Click "Create" to add the mitigation task
You will be directed to the task details page for further documentation
Mitigation Task Details
The mitigation task details page contains comprehensive information about a specific mitigation activity:
Basic Information - Name, description, priority, and due date
Assignment - Individuals responsible for implementation
Status - Current state of the implementation process
Related Items - Associated risks, controls, and other elements
Attachments - Supporting documentation and evidence
Comments - Discussion and updates related to the task
Creating a Mitigation from a Risk
To create a mitigation task directly from a risk:
Navigate to the risk details page
In the Risk Treatment section, ensure "Mitigate" is selected as the strategy
Click "Add Mitigation Task"
Enter the mitigation task details as described above
The task will be automatically linked to the risk
Save the mitigation task
Mitigation Task Assignment
To designate responsibility for implementing a mitigation task:
Navigate to the mitigation task details page
In the Assignment section, select:
Primary owner (responsible for overall implementation)
Additional stakeholders (contributing to implementation)
Set or update the target completion date
Save the assignment information
The system will notify assigned individuals
Mitigation Task Status Management
Mitigation tasks typically follow this lifecycle:
Open - Initially created, not yet started
In Progress - Implementation activities have begun
Completed - Implementation finished, pending verification
Verified - Confirmed as successfully implemented
Deferred - Temporarily postponed for valid reasons
To update a mitigation task's status:
Navigate to the mitigation task details page
Click "Update Status"
Select the new status
Provide comments explaining the status change
Upload supporting documentation if applicable
Save the status update
Implementing Mitigations
Planning Implementation
To develop a detailed implementation plan:
Navigate to the mitigation task details page
In the Implementation Plan section, document:
Specific steps required
Timeline for each step
Required resources
Potential challenges
Success criteria
Save the implementation plan
Update as needed during the implementation process
Tracking Implementation Progress
To monitor implementation activities:
Navigate to the mitigation task details page
Add progress updates in the Comments section
Update the completion percentage
Document completed steps
Identify any challenges or delays
Adjust the plan if necessary
Documenting Implementation Evidence
To record proof of implementation:
Navigate to the mitigation task details page
Select the "Attachments" tab
Click "Add Attachment"
Choose the attachment type:
Document upload
Screenshot
Link to existing document
External reference
Provide a description explaining how the attachment demonstrates implementation
Upload or link the attachment
Save the attachment record
Verifying Mitigations
Verification Process
To confirm that a mitigation task has been properly implemented:
Navigate to the mitigation task details page
Review the implementation evidence
Conduct testing to verify effectiveness if necessary
Document the verification process:
Tests performed
Results observed
Conclusion regarding effectiveness
If successfully implemented, update the status to "Verified"
If not fully implemented, provide feedback and return to "In Progress"
Effectiveness Assessment
To evaluate whether a mitigation has reduced the associated risk:
Navigate to the mitigation task details page
In the Effectiveness Assessment section, document:
Whether the mitigation has been fully implemented
Whether it has reduced the risk as expected
Any remaining concerns or residual issues
Recommendations for further action if needed
Save the assessment information
Update the residual risk assessment on the related risk
Mitigation Integration
Linking Mitigations to Risks
Mitigation tasks are typically created in response to identified risks:
Navigate to the mitigation task details page
Select the "Risks" tab
Click "Link Risks"
Search for and select relevant risks
Save the associations
The mitigation task will appear in the related risks
Connecting Mitigations to Controls
To associate mitigation tasks with security controls:
Navigate to the mitigation task details page
Select the "Controls" tab
Click "Link Controls"
Search for and select relevant controls
Save the associations
The task will be visible in the control details
Mitigation Reporting
Standard Reports
The system provides several standard mitigation reports:
Mitigation Register - Complete inventory of all mitigation tasks
Mitigation Status Report - Overview of implementation progress
Overdue Mitigations - Tasks past their target completion date
Mitigations by Owner - Tasks grouped by responsible individuals
Mitigation Effectiveness - Assessment of mitigation outcomes and impact
Custom Reports
To create a custom mitigation report:
Navigate to the Reports section
Click "Create Custom Report"
Select report type (Mitigations)
Choose filtering and grouping options
Select display columns and sorting
Generate the report
Export to PDF, Excel, or CSV format
Best Practices
Mitigation Planning
Be specific - Clearly define what needs to be done
Address root causes - Focus on underlying issues, not just symptoms
Set realistic timelines - Allow adequate time for implementation
Consider dependencies - Identify relationships between mitigations
Define success criteria - Establish how effectiveness will be measured
Mitigation Assignment
Choose appropriate owners - Assign to individuals with relevant expertise
Ensure authority - Verify that owners have the power to implement changes
Balance workload - Avoid overloading specific individuals
Clarify expectations - Ensure owners understand what's required
Provide resources - Ensure necessary tools and support are available
Mitigation Implementation
Follow the plan - Adhere to the defined implementation steps
Document progress - Record all activities and milestones
Address obstacles - Promptly resolve implementation challenges
Communicate regularly - Keep stakeholders informed of status
Adapt as needed - Adjust plans based on new information or challenges
Mitigation Verification
Be thorough - Conduct comprehensive testing of implemented mitigations
Remain objective - Base verification on evidence, not assumptions
Document results - Record all verification activities and outcomes
Consider long-term effectiveness - Evaluate sustainability of solutions
Learn from experience - Use insights to improve future mitigations
Troubleshooting
Common Issues
Vague mitigation plans - Ensure specific, measurable implementation steps
Unrealistic deadlines - Adjust timelines to reflect actual requirements
Inadequate resources - Secure necessary personnel and tools
Implementation delays - Address obstacles promptly and adjust plans
Ineffective mitigations - Revisit mitigation strategy if risk isn't reduced
Getting Support
If you encounter issues with the Mitigations component:
Check the in-app help documentation
Contact your organization's system administrator
Submit a support ticket through the AskInfosec support portal
Conclusion
Effective risk mitigation is essential for reducing your organization's security exposure and demonstrating due diligence in addressing identified risks. The Mitigations component provides the tools and structure needed to plan, implement, track, and verify risk reduction activities in a consistent, comprehensive manner.
By following the processes outlined in this guide, you can establish a robust mitigation program that helps your organization address security risks, implement improvements, and strengthen your overall security posture.
Last updated