Overview
Implement automated generation of the Risk Exposure Table (RET) from security assessment findings.
Source Details
Scope
- Ingest security weaknesses and deficiencies identified during assessment testing
- Calculate risk scores based on likelihood and impact
- Output FedRAMP SAR Appendix A-compatible RET
Acceptance Criteria
- Accept raw findings (vulnerabilities, control deficiencies, gaps) as input
- Auto-calculate risk exposure using FedRAMP risk methodology
- Generate structured RET with risk ratings, remediation timeline, and owner assignment
- Export to Excel/CSV/JSON
Linked Linear Issue
Linear: GRC-59 — https://linear.app/grc-engineering-club/issue/GRC-59/automated-ret-risk-exposure-table-generation-based-on-assessment
Overview
Implement automated generation of the Risk Exposure Table (RET) from security assessment findings.
Source Details
Scope
Acceptance Criteria
Linked Linear Issue
Linear: GRC-59 — https://linear.app/grc-engineering-club/issue/GRC-59/automated-ret-risk-exposure-table-generation-based-on-assessment