Risk Origins
A risk’s origin — Design, Test, or Monitor — is a label that records where the risk first came from. It does not drive scoring, layout, or separate field sets.
A new risk has no origin until it has evidence. As soon as the first evidence item is recorded against a risk — whether that’s while creating the risk or any time afterward, on the Risk tab’s Evidence card — the risk’s origin is set to match that evidence’s source. A risk with no origin yet shows — wherever the origin would normally appear. Evidence recorded with source Manual doesn’t set an origin, since there is no matching risk type; the risk stays without one until Design, Test, or Monitor evidence is added. Once a risk has an origin, later evidence never changes it.
Scoring is driven by the evidence attached to the risk and the Threat Library entities linked to it — attack paths drive Likelihood, damage scenarios drive Impact — plus the Control Library entries that reduce the residual score. Design, Test, and Monitor risks all share the same Risk tab layout and the same evidence model. Evidence items carry their own source — Design, Test, Monitor, or Manual — independent of the risk’s origin.
| Origin | Meaning | Typical evidence |
|---|---|---|
| Design | Risk originated from threat modeling or TARA analysis | Threat scenarios, attack paths, damage scenarios from the Threat Library |
| Test | Risk originated from a security test result | Test findings with CVSS scores |
| Monitor | Risk originated from vulnerability monitoring | CVE references, vulnerability IDs, CVSS scores, Clause-8 weakness state |
The origin appears in the Origin column of the risks list, as Risk Origin on the Risk tab, and in PDF reports — showing — on any risk that has no evidence yet.