Residual risk score calculation with non-compliant controls

Trey7
Tera Contributor

Where in the configuration does the residual risk calculation take into account any non-compliant controls? My assumption is that the residual risk score should automatically be lowered if there is an associated non-compliant control.

5 REPLIES 5

Thank you! Where can the Calculated Risk Factor & Calculated Risk Score be viewed and can those be configured?