🎉 VSEC Test v4.0.1 is now live! Release Notes ↗
Risk Origins

Risk Origins

Every risk is created with one of three originsDesign, Test, or Monitor — chosen at creation and fixed for the lifetime of the risk. The origin is a label that records where the risk first came from; it does not drive scoring, layout, or separate field sets.

Scoring is driven by the evidence attached to the risk and the Threat Library entities linked to it — attack paths drive Likelihood, damage scenarios drive Impact — plus the Control Library entries that reduce the residual score. Design, Test, and Monitor risks all share the same Risk tab layout and the same evidence model. Evidence items carry their own sourceDesign, Test, Monitor, or Manual — independent of the risk’s origin.

OriginMeaningTypical evidence
DesignRisk originated from threat modeling or TARA analysisThreat scenarios, attack paths, damage scenarios from the Threat Library
TestRisk originated from a security test resultTest findings with CVSS scores
MonitorRisk originated from vulnerability monitoringCVE references, vulnerability IDs, CVSS scores, Clause-8 weakness state

The origin appears in the Origin column of the risks list, as Risk Origin on the Risk tab, and in PDF reports.

In This Section

Last updated on