🎉 VSEC Test v4.0.1 is now live! Release Notes ↗

Design Risks

A Design risk originated from threat modeling or TARA (Threat Analysis and Risk Assessment) — including risks accepted from a Threat Modeling run, which arrive with Design evidence and a deterministic score. The origin is a label and does not change how the risk is scored — all scoring is driven by evidence and controls via the evidence model.

Threat Library Links

Design risks are typically linked to Threat Library entities from the Risk tab:

  • Threat scenarios — the scenario being analyzed.
  • Attack paths — named routes built from step sequences capturing how the threat could be realized; a path’s feasibility derives from the five attack-potential factors on its steps.
  • Damage scenarios — named outcomes (description + impact rating) capturing what happens if the threat succeeds.
  • Controls — Control Library entries applied to drive down the residual score.

These links feed the Model Health card and contribute to the risk’s scoring dials: attack feasibility → Likelihood; damage scenario impact → Impact. See Model Health.

Evidence

Design risks accumulate Design evidence items that carry the finding’s detail. Each item includes a source (Design), summary, CVSS score (where applicable), Clause-8 weakness state, reference, and date. New evidence re-scores the risk automatically.

Legacy TARA Info Fields

Risks created before the evidence model migration may still carry flat TARA Info fields — threat scenario text, original/residual risk scores, justification, recommended action. These fields are preserved for back-compatibility, but they no longer appear on the Risk tab — they are visible only in revision-history snapshots (open an entry on the Activity tab). They are not used for scoring on the new evidence model.

Last updated on