Add the entities a risk area assesses
Choose the processes, assets and suppliers the risk area should cover before you start assessing.
Before you can assess anything, you choose which entities the risk area should risk assess. Entities are the concrete things risk sits on: processes, assets and systems, and suppliers. Once they are added, you can start adding risk scenarios to them.
- Open the risk area and go to the Operational overview.
- Click Add entities.
- Select the processes, assets and systems and suppliers/legal entities the area should cover.
- Click Save.

Keep the selection honest. An area concerned only with supplier security should not be pulling in processing activities, while an area covering information security may well need all three types.
You can add more entities later as your scope grows.