The risk score has 3 main factors:
* Business Risk. This is calculated using several factors including Usage Type (Corporate/Personal), Reputation (TALOS data), Financial Viability score, and type of Data Stored (Structured Database/Unstructured Documents).
* Usage Type. This is unique to the organization. Higher usage increases the risk of the application for this organization
* Vendor Compliance. If the Vendor is compliant with regulations and attained certification (eg. FedRAMP, HIPAA) this reduces the overall risk score.
If you click on the application in the App Discovery report, you'll be able to see the details of the scoring by clicking on the > by the factors. If you think that the rating is incorrect, you can submit your feedback by clicking on the Help us Improve option under risk detail.
That would mean, an application with a High risk, it might not mean that the application has a security issue, this could be because of the type of data the application handles.
Best Regards,
Esha Goyal