Skip to main content

Governance artifact

Gemara Layer 3

RiskCatalog

Risk

Purpose

Organizational risk categories, severity levels, and risk appetite definitions.

Role

Risks are how the organisation talks about exposure it owns—severity, appetite, owners and threats that materialise them.

Examples

Disclosure of non-public or sensitive information

A FOSS risk catalog records data-leakage as High severity under an Information Protection group with Low appetite, owned jointly by contributors and project administrators, and linked to the sensitive-data-disclosure threat. Policy lists it as a mitigated risk with assessment and enforcement methods. That organisational category aligns with FINOS OSR Data Leakage Risk.

Source: Disclosure of Non-Public or Sensitive Information (data-leakage) in FOSS Contribution Risk Catalog; Data Leakage Risk in FINOS Open Source Readiness.

Legal risk (open source)

License non-compliance, unauthorized IP publication, contributor-agreement obligations and export-control failures are Layer 2 threats that materialise as organisational Legal Risk—consequences from actions that violate laws, regulations or binding agreements.

Source: Legal Risk in FINOS Open Source Readiness; compare Legal Risk in Risk First (IP, licensing, contracts).

Reputational risk

Harm to organisational credibility from contribution quality, public conduct or abandoned projects. OSR treats this as a first-class open-source risk; Risk First frames the same exposure as reputational harm attendant to how the organisation shows up externally.

Source: Reputational Risk in FINOS Open Source Readiness; Reputational Risk in Risk First.

Security risk

Risk First names Security Risk as loss from hostile agents and events inside or outside the system—a Layer 3 category under which contribution and platform threats (credential disclosure, supply-chain compromise) roll up for owners and appetite.

Source: Security Risk in Risk First; see also the glossary of risk types.

Operational risk

Loss from inadequate or failed processes, people, systems or external events. Both OSR and Risk First use this umbrella for process and control failures that governance is meant to reduce—distinct from any single Layer 2 threat title.

Source: Operational Risk in FINOS Open Source Readiness; Operational Risk in Risk First.

Anti-patterns

Risks with no owners

A severity label and no accountable human. Appetite without ownership is a spreadsheet, not governance.

Threat catalogue renamed as risk

Copying Layer 2 threat titles into Layer 3 without organisational severity, appetite or owners. The layers collapse.

References