Software Technologies Inventory and Attributes - Risk attributes for the Software Technologies Inventory
Software Technologies Inventory and Attributes
Chapter 28. Risk attributes for the Software Technologies Inventory
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| End of Support Risk | Exposure arising from a technology running past, or approaching, the end of supplier support — foreseeable, dateable, and commonly ignored. |
| Concentration Risk | Exposure arising when too much of the estate depends on a single technology, supplier, or person. |
| Mitigation Plan | What the enterprise intends to do about a recorded risk, which converts an observation into a commitment. |
Quick Q&A
Question: Why is End of Support Risk separate from End of Support Date?
Read More Below
Risk attributes record the exposure each software technology carries and what the enterprise intends to do about it.
| Attribute Name | Maturity | Description and Notes |
|---|---|---|
| End of Support Risk | Walk | Description — The exposure arising from the technology running past, or approaching, the end of supplier support. Benefit(s) — The most foreseeable risk in the portfolio and the most commonly realized. Expressing it as a judgment rather than a date makes it actionable. Source — Calculated or Manual. Examples — Critical, High, Moderate, Low, None Notes — Calculable from end-of-support proximity, criticality tier, and dependent application count. Two technologies with the same date can carry very different risk. |
| Overall Risk Rating | Run | Description — A composite judgment of the total risk the technology represents. Benefit(s) — Allows portfolio-level risk comparison and prioritization across technologies that are otherwise hard to rank. Source — Calculated. Notes — Publish the method alongside the rating; an unexplained composite invites argument about the number rather than action on it. |
| Concentration Risk | Run | Description — The exposure created when a disproportionate share of the estate depends on this technology, its supplier, or a single person. Benefit(s) — Surfaces systemic exposure that per-technology assessment misses entirely. Source — Derived or Manual. Notes — Derivable from dependent application counts and supplier groupings across the portfolio. |
| Single Point of Failure Indicator | Run | Description — Whether the technology represents a single point of failure for the systems that depend on it. Benefit(s) — Identifies where resilience investment would have disproportionate effect. Source — Manual or Derived. Notes — Assess against the technology as deployed, not as it could theoretically be deployed. |
| Risk Mitigation Plan | Run | Description — What the enterprise intends to do about the recorded risk. Benefit(s) — Converts an observation into a commitment, and makes unmitigated risks visible as a set. Source — Manual. Notes — A recorded risk with no mitigation and no accepted-risk decision is an open item, and should be reportable as one. |
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Risk attributes for the Software Technologies Inventory | Software Technologies Inventory and Attributes. https://if4it.org/best-practices/software-technologies-inventory-and-attributes/risk-attributes-for-the-software-technologies-inventory/ (accessed 2026-07-28).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers