Risk Origins
Every risk is created with one of three origins — Design, Test, or Monitor — chosen at creation and fixed for the lifetime of the risk. The origin is a label that records where the risk first came from; it does not drive scoring, layout, or separate field sets.
Scoring is driven by the evidence attached to the risk and the Threat Library entities linked to it — attack paths drive Likelihood, damage scenarios drive Impact — plus the Control Library entries that reduce the residual score. Design, Test, and Monitor risks all share the same Risk tab layout and the same evidence model. Evidence items carry their own source — Design, Test, Monitor, or Manual — independent of the risk’s origin.
| Origin | Meaning | Typical evidence |
|---|---|---|
| Design | Risk originated from threat modeling or TARA analysis | Threat scenarios, attack paths, damage scenarios from the Threat Library |
| Test | Risk originated from a security test result | Test findings with CVSS scores |
| Monitor | Risk originated from vulnerability monitoring | CVE references, vulnerability IDs, CVSS scores, Clause-8 weakness state |
The origin appears in the Origin column of the risks list, as Risk Origin on the Risk tab, and in PDF reports.