🎉 VSEC Test v4.3.1 is now live! Release Notes ↗

Risk Origins

A risk’s origin — Design, Test, or Monitor — is a label that records where the risk first came from. It does not drive scoring, layout, or separate field sets.

A new risk has no origin until it has evidence. As soon as the first evidence item is recorded against a risk — whether that’s while creating the risk or any time afterward, on the Risk tab’s Evidence card — the risk’s origin is set to match that evidence’s source. A risk with no origin yet shows — wherever the origin would normally appear. Evidence recorded with source Manual doesn’t set an origin, since there is no matching risk type; the risk stays without one until Design, Test, or Monitor evidence is added. Once a risk has an origin, later evidence never changes it.

Scoring is driven by the evidence attached to the risk and the Threat Library entities linked to it — attack paths drive Likelihood, damage scenarios drive Impact — plus the Control Library entries that reduce the residual score. Design, Test, and Monitor risks all share the same Risk tab layout and the same evidence model. Evidence items carry their own source — Design, Test, Monitor, or Manual — independent of the risk’s origin.

OriginMeaningTypical evidence
DesignRisk originated from threat modeling or TARA analysisThreat scenarios, attack paths, damage scenarios from the Threat Library
TestRisk originated from a security test resultTest findings with CVSS scores
MonitorRisk originated from vulnerability monitoringCVE references, vulnerability IDs, CVSS scores, Clause-8 weakness state

The origin appears in the Origin column of the risks list, as Risk Origin on the Risk tab, and in PDF reports — showing — on any risk that has no evidence yet.

In This Section

Last updated on