SECURITY Signal 410
Risk-Analysis-Editor: Open-source risk analysis editor supporting EBIOS RM, GDPR DPIA (CNIL), ISO 27005 and custom methodologies
An open-source, browser-based risk analysis editor now supports multiple compliance frameworks and custom methodologies in a single offline-capable tool.
Engineers responsible for security risk assessments can replace ad-hoc spreadsheets with a structured, portable editor that enforces consistent scoring and visualization. The tool’s offline operation and open file format reduce dependency on proprietary GRC platforms while still aligning with ISO 27005, EBIOS RM, or GDPR DPIA workflows. Adoption costs are low, just a double-click, but the tool stops short of full framework automation, leaving methodology interpretation to the user.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Single HTML file runs offline in any browser, eliminating installation and server dependencies.
Exports to a documented .rae.json format with schema validation, enabling version control and interoperability.
Configurable scoring grids and trajectory views support ISO 27005, EBIOS RM, GDPR DPIA, or custom risk matrices.
THE READ
What the cluster adds up to.
The editor shifts risk analysis from spreadsheets to a structured web app that enforces consistent scoring and visualization. Engineers can define custom risk matrices, link controls to risks, and track residual risk trajectories without leaving the browser. The tool’s offline capability and single-file distribution simplify deployment, but its reliance on manual data entry means it won’t scale for large, dynamic risk registers without additional scripting or integration.
By supporting ISO 27005, EBIOS RM, and GDPR DPIA methodologies, the editor bridges gaps between compliance frameworks. Users configure the grid’s dimensions, labels, and thresholds to match their chosen standard, but the tool doesn’t automate framework-specific steps, like CNIL’s PIA process, leaving interpretation to the analyst. The provided templates offer starting points, but organizations must still adapt them to their internal policies, which may require additional validation effort.
The .rae.json file format and JSON schema provide a portable, version-controlled alternative to proprietary GRC exports. Engineers can commit analyses to Git, validate them programmatically, or build custom tooling around the format. However, the format’s documentation is currently French-only, and the tool lacks built-in collaboration features, making it better suited for individual or small-team use cases rather than enterprise-wide risk management.
Visualization features like trajectory arrows and interactive matrices help engineers communicate risk reduction progress to stakeholders. The tool’s drag-and-drop interface and customizable layouts make it easier to spot unmitigated risks or coverage gaps, but its static output (HTML/JSON) means real-time dashboards or automated alerts would require external tooling. For consulting engagements or workshops, the tool’s simplicity is an asset; for continuous monitoring, it’s a starting point rather than a complete solution.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER