🎉 VSEC Test v4.0.1 is now live! Release Notes ↗

Test Risks

A Test risk originated from a security test result. The origin is a label and does not change how the risk is scored — all scoring is driven by evidence and controls via the evidence model.

Evidence

Test risks accumulate Test evidence items. Each item carries:

FieldDescription
SourceTest
SummaryNarrative description of the finding
CVSS scoreUsed to derive the Likelihood dial
Clause-8 weakness stateEvent, Weakness, Vulnerability, or Not Applicable (a rationale is required for Not Applicable)
ReferenceTest report identifier (e.g. a report id or ticket)
DateStamped automatically when the evidence item is created

New evidence re-scores the risk automatically. See Risk Details for how CVSS scores feed the scoring model.

Controls

Link Control Library entries to the risk from the Risk tab to drive down the residual score.

Legacy Test Info Fields

Risks created before the evidence model migration may still carry flat Test Info fields — test type, report URL, test reference, CVSS score, description, test steps, expected/actual result. These fields are preserved for back-compatibility, but they no longer appear on the Risk tab — they are visible only in revision-history snapshots (open an entry on the Activity tab). One exception feeds scoring: when no evidence item carries a CVSS score, the legacy Test CVSS score is used as a fallback.

Last updated on