ssm.ro Docs
Security, Infrastructure & OperationsRisk Management

Risk Management Methodology

Qualitative risk assessment framework: Likelihood × Impact, annual review

Risk Assessment Framework

SSM.ro applies a qualitative risk assessment based on the Likelihood × Impact scale with three levels: Low / Medium / High.

Each identified risk is mapped to existing controls; residual risk represents the remaining exposure after these controls are applied.

Assessment Process

  1. Identification — risks are identified based on analysis of the architecture, components, data flows, and known threats to the SSM.ro platform
  2. Assessment on two dimensions:
    • Likelihood: how likely it is to materialize — Low (L) / Medium (M) / High (H)
    • Impact: the consequence of materialization — Low (L) / Medium (M) / High (H)
  3. Control mapping — each risk is mapped to the controls in force that mitigate it
  4. Residual risk — the remaining exposure after controls; the goal is for all residual risks to be at the Low level
  5. Approval — residual risks are formally accepted, with a documented approval date

Review Framework

The risk register is reviewed:

  • At least annually
  • Following any significant architectural change

The assessment document is versioned, dated, and classified Confidential.

Scope

The assessment covers the Shared model (multi-tenant). Enterprise deployments (single-tenant/dedicated) are assessed separately under a distinct set of controls.

Risk Categories Assessed

CategoryRisk examples
Access and identityUnauthorized account access, unauthorized access to documents in object storage
AvailabilityService unavailability, capacity exhaustion
Code integrityDeployment failure, vulnerable dependencies, insecure code
DataLoss of relational data, loss of documents
CredentialsExposure of secrets and credentials
AuditLog tampering, loss of signature trail
Third partiesSub-processor compromise
ComplianceData retention, data subject rights, secure transport