A risk model defines the factors assessed and the relationships between them. This section explains threats, vulnerabilities, predisposing conditions, scenarios, likelihood and impact, then connects those ideas to the CSFaaS assessment workflow.
Choose and document the model before comparing scores. Reviewers need to understand the same scenario boundaries, criteria and assumptions for their results to be meaningfully compared.