Every studio's risks in one register
The Risk Register consolidates the findings you have already produced in PlayCISO's other security-architect tools β the Threat Model, Architecture Studio and Design Review Workbench β into a single, severity-ranked list with owner and status tracking, then exports it in board-ready and machine-readable formats. It is an aggregator of your PlayCISO work, not a scanner of your live environment.
What it does
One view across three tools
Pulls findings from your Threat Model, Architecture Studio and Design Review Workbench into a single ranked list, tagged by source.
Severity, residual & ownership
Each row carries a severity band, a normalised score, residual risk where set, owner and status β sorted worst-first.
Board-ready & machine-readable export
Export to CSV, SARIF, OSCAL, Open Threat Model, OWASP Threat Dragon, or a printable report.
How it works
- 1Use the Threat Model, Architecture Studio or Design Review Workbench to produce findings.
- 2Open the Risk Register β it reads what those tools saved in your browser and merges everything into one ranked list.
- 3Filter by source, set residual risk, owners and status, and see the critical/high/medium/low counts.
- 4Export to CSV, SARIF, OSCAL, OTM or Threat Dragon, or print the summary report for a board pack.
Honest about what this is
- A consolidation and export layer over the risk work you do in PlayCISO's other tools.
- Turns scattered threat-model, architecture and design-review findings into one board-ready register.
- β Not a vulnerability scanner β it starts empty until you have findings from the other tools, and reads nothing from your live systems.
FAQ
Where do the risks come from?
From the other PlayCISO security-architect tools you have already used in the same browser β the Threat Model, Architecture Studio and Design Review Workbench. The Risk Register reads what those tools saved locally and consolidates it into one view. It does not scan your environment or import anything from outside PlayCISO.
What if I have not used those tools yet?
Then the register starts empty. It is an aggregator, so you build a threat model, run an architecture review or a design review first, and their findings then appear here ranked together.
What does it show for each risk?
Its source tool, a severity band (critical / high / medium / low), a normalised score, residual risk where you set one, the owner and the status, plus references like CWE, ASVS or framework control IDs.
What can I export?
CSV, SARIF, OSCAL, Open Threat Model (OTM), an OWASP Threat Dragon file, and a printable summary report.
Is it free?
The interactive register is part of a paid plan. Any PlayCISO plan unlocks it, along with the other security-architect studios.