Loading
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Create Risk Scenario for IT Compliance

          Create Risk Scenario for IT Compliance

          Build a centralized library of reusable risk templates to ensure consistency across your organization. Creating risk scenarios saves time and standardizes the data when your compliance team registers new vulnerabilities.

          Required Editions

          Available in: Lightning Experience
          Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service.
          User Permissions Needed
          To create risk scenarios: Compliance Admin permission set

          A risk scenario is a reusable template that describes a category of risk your organization faces, like phishing attacks, data retention failures, or supply chain breaches. Storing scenarios in the Risk Scenario Library lets your team apply the same definition, category, and source framework every time someone registers a new risk, so risks of the same type stay consistently classified across your Risk Register.

          1. From App Launcher, go to the IT Compliance app and select Risk Scenario Library.
          2. Click Add and then enter the Name, Description, Category, and the Source Framework.
          3. Save your changes.
          Example: a phishing risk scenario
          Example: a phishing risk scenario

          Suppose your organization wants to standardize how it tracks the threat of phishing attacks across every business unit and vendor. You create a single risk scenario in the library with these values:

          • Name: Phishing Attack
          • Description: Attackers attempt to steal credentials or deliver malware by impersonating a trusted source through email, SMS, or messaging.
          • Category: Cybersecurity
          • Source Framework: ISO/IEC 27001:2022

          From now on, anyone registering a phishing-related risk against a specific business unit, vendor, or asset can pick this scenario as the template. The risk record inherits the description, category, and framework from the scenario, so phishing risks stay classified the same way across your entire Risk Register, no matter who creates them or when.

           
          Loading
          Salesforce Help | Article