08/05/2026
Two major challenges underpinned the development of a risk management tool:
1. the increasing complexity of performing a risk analysis that would allow for the adoption of effective and efficient measures, the lack of coherence in calculating the residual risk based on the inherent risk and the security measures adopted, and
2. the increasing number of regulatory requirements, but also the redundancy of many of them.
With over 20 years of experience in information security management, Florin-Mihai Iliescu, auditor and information security specialist at Info-Logica Silverline, designed and developed the risk management platform - COBRA (Control Based on Risk Assessment).
Risks are defined for each category of information resource, which offers the possibility for the platform to also be used for drawing up the register of information systems.
Once the risk analysis is complete, the security measures are translated into policies and procedures that can be managed through the text editor integrated into the platform, an editor that also offers the possibility of correlating documents with various requirements from the standards and regulations applicable to the industry specific to each organization. Correlating documents with these regulatory requirements allows the generation of an automatic report with the degree of compliance, and the documents in which the requirements from the standards or regulations were addressed.
The implementation of security measures is followed by a monitoring and control process. COBRA also supports these processes through the possibility of defining audit tests. Once defined, these tests are saved in a library, saving the effort required for future audits. In addition, the organization always has a complete picture of the reason for which each audit test was defined, as it is linked to a security measure or control, which in turn is related to the reduction of a certain risk.
I wanted this tool to be a complete solution for managing the risk management framework and to meet this goal we also created the facility for recording business processes that the user can associate with the information resources already defined in the platform. Using the process documentation module provides support for: compliance with regulations requiring the inventory and classification of processes, documenting the personal data map required by the GDPR, business continuity planning, etc. Of course, with the possibility of inventorying information resources, the categories of personal data will also be available in COBRA, and the impact analysis on them (DPIA) will be able to be done as easily as any other risk analysis.