All Apps and Add-ons

How do you form the CSV file for the risk register?

Justin_Grant
Contributor

What is the format of the CSV file for the risk register in the Creative Commons PCI app?

0 Karma
1 Solution

Pete_Bassill
Path Finder

Hey Justin

The format should be pretty straight forward. The structure of the file:

rpos (Risk Position, used for creating the top 10 risk categories) rdetail (The guts of the Risk entry within the register) rimpact - This is the Risk Impact on a scale of 1 (little impact) to 5 (heavy impact) rprob - This is Risk Probability or the likelyhood of the risk occuring, again 1 to 5 rval - This is the Risk Value, a multiple of rimpact and rprob.

Below is a head of the log file. I tend to store this as a monitored file in /var/log/srisk.

rpos,rdetail,rimpact,rprob,rval 1,"Legacy systems, unsupported software being highly vulnerable to attack",5,4,20

Hope that helps, enjoy the User Conference.

Pete

View solution in original post

Pete_Bassill
Path Finder

Hey Justin

The format should be pretty straight forward. The structure of the file:

rpos (Risk Position, used for creating the top 10 risk categories) rdetail (The guts of the Risk entry within the register) rimpact - This is the Risk Impact on a scale of 1 (little impact) to 5 (heavy impact) rprob - This is Risk Probability or the likelyhood of the risk occuring, again 1 to 5 rval - This is the Risk Value, a multiple of rimpact and rprob.

Below is a head of the log file. I tend to store this as a monitored file in /var/log/srisk.

rpos,rdetail,rimpact,rprob,rval 1,"Legacy systems, unsupported software being highly vulnerable to attack",5,4,20

Hope that helps, enjoy the User Conference.

Pete

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...