Risk identification is performed in the Risk Profiling tab of each risk. Here you characterise the risk so it can be compared, filtered and analysed consistently across the registry. Every dropdown draws from your workspace catalogues.

1. Contextual information

  • Security Domain: the area of security the risk pertains to.
  • Business Attribute: the business function or attribute affected.
  • Risk Category: the classification of the risk in your taxonomy.

2. Threat details

  • Threat Origin: the source of the threat (internal, external, environmental).
  • Threat Actor: the individual or entity behind the threat.
  • Threat Actor Motivation: the intent (financial gain, disruption, espionage).
  • Threat Vector: the pathway through which the threat is executed.
  • STRIDE Threat Action: the action classified by the STRIDE framework (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege).
  • Threat Action: the specific action taken by the threat actor.

3. Impact assessment

  • Victims Quantification: the number of potential victims or entities impacted.

4. Threats from your database

You can also link concrete threats to the risk with Add Threats: import entries from your workspace's Threat Attacks Database (Databases module) so the profile references the same threat definitions used elsewhere in the platform.

5. Additional information

Use the Other Information text box for any supplementary details about the risk.

Together these settings build a finely tuned, actionable risk profile: security domain, business attributes, threat details, impact quantification and linked threats give every reader the same precise picture of the risk.