<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Risk Assessment workflow in Governance and Compliance Manager in SAS Risk Management</title>
    <link>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971625#M541</link>
    <description>&lt;P&gt;the second approach is the likely more effective approach. Building your inventory of assets, risks, controls, threats etc, allows you to reuse those for assessments and builds up a history of where those are used for further analysis later on.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2025 12:00:53 GMT</pubDate>
    <dc:creator>KPotter</dc:creator>
    <dc:date>2025-07-29T12:00:53Z</dc:date>
    <item>
      <title>Risk Assessment workflow in Governance and Compliance Manager</title>
      <link>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971427#M540</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am a new user on Governacne &amp;amp; Compliance Manager. We are considering following two approaches to standardize our regular risk assessments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Collect asset information against each risk assessment activity and add risks, threats and vulnerabilities against each risk assessment every time and evaluate control effectiveness. In this approach risks, assets, and vulnerabilities might have duplications, but we can start with tiny steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Collect complete asset inventory, potential risks, threats and vulnerabilities and upload into the system. For each risk assessment we can select associated assets, risks, threats and vulnerabilities from already uploaded data and evaluate control effectiveness against each risk assessment exercise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please guide what is the right approach to move forward with a consistent and sustainable approach.&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 08:15:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971427#M540</guid>
      <dc:creator>MohsinRaza</dc:creator>
      <dc:date>2025-07-24T08:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment workflow in Governance and Compliance Manager</title>
      <link>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971625#M541</link>
      <description>&lt;P&gt;the second approach is the likely more effective approach. Building your inventory of assets, risks, controls, threats etc, allows you to reuse those for assessments and builds up a history of where those are used for further analysis later on.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 12:00:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971625#M541</guid>
      <dc:creator>KPotter</dc:creator>
      <dc:date>2025-07-29T12:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Assessment workflow in Governance and Compliance Manager</title>
      <link>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971669#M542</link>
      <description>Thanks KPotter</description>
      <pubDate>Wed, 30 Jul 2025 06:32:50 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Risk-Management/Risk-Assessment-workflow-in-Governance-and-Compliance-Manager/m-p/971669#M542</guid>
      <dc:creator>MohsinRaza</dc:creator>
      <dc:date>2025-07-30T06:32:50Z</dc:date>
    </item>
  </channel>
</rss>

