Skip to main content

Drata's Risk Library (New Experience)

Updated this week

The Risk Library contains a predefined set of risks based on industry standards such as NIST SP 800-30, ISO 27005, OCR SRA, and other recognized frameworks. These risks are designed to help you quickly build and populate your Risk Register.

You can add any risk from the Risk Library to your Risk Register. Once a risk is added, it becomes part of your register and can be assessed, assigned, and managed like any other risk.

Standard risks in the Risk Library are read-only and cannot be edited directly. After adding a risk to your Risk Register, you can modify its details to reflect your organization’s specific context. If you need to reference Drata’s original, standardized risk descriptions, you can always view them in the Risk Library.

Add a risk to your register

You can add a risk to your register by:

  1. Navigate to Risk Management.

  2. Select the Risk Register you want to add the risk to.

  3. Open the Library tab.

  4. Do one of the following:

    • Select the ellipsis (⋯) next to a risk and choose Add to register, or

    • Select the checkbox next to one or more risks, then click Add to register.

Did this answer your question?