Security, Infrastructure & OperationsRisk Management
Risk Management Methodology
Qualitative risk assessment framework: Likelihood × Impact, annual review
Risk Assessment Framework
SSM.ro applies a qualitative risk assessment based on the Likelihood × Impact scale with three levels: Low / Medium / High.
Each identified risk is mapped to existing controls; residual risk represents the remaining exposure after these controls are applied.
Assessment Process
- Identification — risks are identified based on analysis of the architecture, components, data flows, and known threats to the SSM.ro platform
- Assessment on two dimensions:
- Likelihood: how likely it is to materialize — Low (L) / Medium (M) / High (H)
- Impact: the consequence of materialization — Low (L) / Medium (M) / High (H)
- Control mapping — each risk is mapped to the controls in force that mitigate it
- Residual risk — the remaining exposure after controls; the goal is for all residual risks to be at the Low level
- Approval — residual risks are formally accepted, with a documented approval date
Review Framework
The risk register is reviewed:
- At least annually
- Following any significant architectural change
The assessment document is versioned, dated, and classified Confidential.
Scope
The assessment covers the Shared model (multi-tenant). Enterprise deployments (single-tenant/dedicated) are assessed separately under a distinct set of controls.
Risk Categories Assessed
| Category | Risk examples |
|---|---|
| Access and identity | Unauthorized account access, unauthorized access to documents in object storage |
| Availability | Service unavailability, capacity exhaustion |
| Code integrity | Deployment failure, vulnerable dependencies, insecure code |
| Data | Loss of relational data, loss of documents |
| Credentials | Exposure of secrets and credentials |
| Audit | Log tampering, loss of signature trail |
| Third parties | Sub-processor compromise |
| Compliance | Data retention, data subject rights, secure transport |