SimpleRisk

Azure Security 1 variation

Open source governance, risk and compliance for managing your organisation's risk register.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Variations

This product is available in the build below. Open it for the operating system, cloud and version detail, or read its deployment guide.

ProductCloudOperating systemVersion
SimpleRisk GRC and Risk Management on Ubuntu 24.04 LTS Azure Ubuntu 24.04 Standard View · Guide

Overview

SimpleRisk is the widely used open source governance, risk and compliance (GRC) platform. Capture and score risks using CLASSIC, CVSS, DREAD or OWASP methodologies, plan and track mitigations and management reviews, run compliance audits against frameworks and controls, manage assets, and report on the whole organisation's risk posture from one shared risk register.

It suits risk and compliance teams, security functions and IT governance teams that want a GRC system they run and own rather than a paid external service, from a single risk owner to a busy multi department programme.

Why the cloudimg image

The cloudimg image installs SimpleRisk behind nginx with PHP 8.3 and a bundled local MariaDB, with the database schema already loaded and the setup wizard already completed and closed, so you land on the sign in page rather than an exposed first run wizard. Nothing sensitive ships: a unique MariaDB password and a unique administrator password are generated on the first boot of every VM and written to a root only file, there is no default administrator login, and the MariaDB database that holds your risk register is bound to loopback only and never exposed to the network. Backed by 24/7 cloudimg support.

Common uses

  • Maintain a shared risk register with CLASSIC, CVSS, DREAD or OWASP scoring
  • Plan and track mitigations and management reviews to reduce risk over time
  • Run compliance audits against frameworks and controls