Each orbiting sphere is an information asset from the risk register — a database, an endpoint, a cloud service, a physical archive — colour-coded by the Annex A control domain that governs it (access control, cryptography, operations security, physical security). An asset's distance from the amber "risk core" at the centre encodes its current risk score (likelihood × impact): the further out, the riskier. Raising control investment continuously pulls assets inward as mitigating controls (encryption, access reviews, monitoring, hardening) are applied; raising threat pressure pushes them back out as new vulnerabilities and attack attempts surface faster than controls can absorb them. A translucent audit ring sweeps outward on a timer — any asset still sitting outside the acceptable-risk boundary when the ring passes it is flagged a non-conformity (it flashes red), exactly as an ISO/IEC 27001 internal or certification audit samples the register and raises a finding for anything above the organisation's risk acceptance criteria.
risk(asset) = likelihood × impact − Σ control_effect × investment
flag_NC(asset) = risk(asset) > acceptance_threshold at time of audit sweep
- Assets in register — how many information assets the ISMS scope currently covers; a larger register spreads the same control budget thinner.
- Control investment — the overall maturity of applied Annex A controls; higher pulls every asset's residual risk down, mirroring a funded risk-treatment plan.
- Threat pressure — the external threat landscape's intensity; higher pushes risk back up regardless of controls, the way a rising attack volume erodes existing safeguards.
- Audit interval — how often the compliance sweep runs; shorter intervals catch drift sooner but each sweep still only samples the register as it stands at that instant.
- Domain filter buttons — dim every asset outside the chosen Annex A control domain so you can inspect one control family (access, cryptography, operations, physical) at a time.
Real-world relevance: this is the core ISO/IEC 27001 risk-treatment cycle — assess risk, apply controls from Annex A, and let a periodic audit programme verify residual risk still sits inside the organisation's declared acceptance criteria.