Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a business process in the Risk Workspace

Create a business process in the Risk Workspace and define the owners, approvers, business criticality, and review frequency for the process.

Before you begin

Role required: Enterprise architect or service owner or itil

About this task

When you create a business process, it is important to ascertain the CIA triad. CIA triad refers to confidentiality, integrity, and availability. The CIA triad is a common model that forms the basis for the development of security systems and policies. These are used for the identification of vulnerabilities and methods for addressing problems and creating solutions.

Procedure

  1. Navigate to All > Risk Workspace > Lists > Business Processes.

  2. Click Create New.

  3. On the form, fill in the fields.

FieldDescription
NameName of the business process.
DescriptionDescription of the business process.
ParentParent business process, if it exists, to create a hierarchy of business processes.
Review frequencyFrequency for reviewing the business process.
Ownership
  
Life cycle stageStage of record in the business life cycle. The stage determines the status and displays the actions. This field is automatically set to Ideation when you save the form for a process in Draft state.
Managed by groupGroup that maintains the business process.
Approval groupGroup that must review and approve the business process.
Owned byUser responsible for the business process. This user is a member of the Managed by group.
Life cycle stage statusStatus of business process within the life cycle stage. This field is automatically set to Under Evaluation when you save the form for a process in Draft state.
Next review datePlanned date on which the business process must be reviewed. The value in this field is automatically set only after the business process is approved.
DescriptionShort description of the business process. The description can include the background, the actual steps, and the interaction of the process.
Business Impact
Business criticality declaredCriticality of the business process based on your subjective assessment. The choices are:- 1- most critical - 2- somewhat critical - 3- less critical - 4- not critical
Business criticality determinedComputed criticality of the business process based on the assessment of the sub-processes. The choices are:- 1- most critical - 2- somewhat critical - 3- less critical - 4- not critical
CIA triad
Impact to confidentialityRisk rating for the risk of loss of confidentiality for the process. The choices are:- High - Medium - Low
Impact to integrityRisk rating for the risk of impact to integrity for the process. The choices are:- High - Medium - Low
Impact to availabilityRisk rating for the risk of loss of availability for the process. The choices are:- High - Medium - Low
  
  1. Right-click and save the form.

    The record moves to the Draft state.

  2. Add related assets to a business process
    Add related business assets to a business process to gain visibility into the IT assets and their performance.

Parent Topic:Using the Risk Workspace

Related topics

Add related assets to a business process