Test Risks
A Test risk originated from a security test result. The origin is a label and does not change how the risk is scored — all scoring is driven by evidence and controls via the evidence model.
Evidence
Test risks accumulate Test evidence items. Each item carries:
| Field | Description |
|---|---|
| Source | Test |
| Summary | Narrative description of the finding |
| CVSS score | Used to derive the Likelihood dial |
| Clause-8 weakness state | Event, Weakness, Vulnerability, or Not Applicable (a rationale is required for Not Applicable) |
| Reference | Test report identifier (e.g. a report id or ticket) |
| Date | Stamped automatically when the evidence item is created |
New evidence re-scores the risk automatically. See Risk Details for how CVSS scores feed the scoring model.
Controls
Link Control Library entries to the risk from the Risk tab to drive down the residual score.
Legacy Test Info Fields
Risks created before the evidence model migration may still carry flat Test Info fields — test type, report URL, test reference, CVSS score, description, test steps, expected/actual result. These fields are preserved for back-compatibility, but they no longer appear on the Risk tab — they are visible only in revision-history snapshots (open an entry on the Activity tab). One exception feeds scoring: when no evidence item carries a CVSS score, the legacy Test CVSS score is used as a fallback.