The Risk information section classifies the scenario so that it can be compared with other risks. Open the risk on its parent demand and select the applicable values from the workspace catalogs.

Describe the affected area

Choose the security domain, business security attribute and risk category. These identify what the scenario concerns; they do not determine its severity on their own.

Describe the threat

Record the risk origin, threat actor, actor motivation, threat vector, STRIDE threat action and other threat action where relevant. Use Link threat to reference an available threat definition from the workspace database.

Choose classifications that fit the facts. An unknown actor or uncertain vector should not be replaced with a confident assumption simply to fill a field. Explain uncertainty in Other profiling information.

Record the affected population

Use Victims quantification where it contributes to the assessment. Explain the scope behind that classification, including whether it concerns people, organisations or another defined population.

Save and review

Save the assessment after updating its fields. Review the profile alongside the risk statement: catalog selections support analysis and filtering, while the statement explains the specific event and consequence being assessed.

Maintain shared definitions in Databases through an authorised catalog editor rather than creating inconsistent wording separately on each demand.