Assessment scope & threat environment
Set the assessment boundary and the baseline threat picture. The country, local and target-attractiveness ratings entered here seed the default likelihood inputs on every risk line.
Document control
Scope of assessment
Exclusions carried from the source methodology: health & safety hazards, financial risk, business impact analysis and business continuity planning are assessed separately. Cyber is limited to physical access control unless set to in-scope above.
Threat environment ratings avg —
Threat category ratings
Critical asset register
Assets are ranked 1–5 against the Impact Severity Criteria — human losses, national reputation, damage to property and disruption to operations. Selecting an asset type pre-loads its typical criticality; override it where the project context differs.
Add asset
Asset register 0
| Ref | Category | Asset | Zone | Exposure | C | Severity class |
|---|
Adversary characterisation
Each adversary is rated on intent, assumed capability and motivation. The threat ranking is the mean of the three, and feeds the historical-likelihood default for scenarios attributed to that adversary.
Adversary profiles
| Adversary type | Source | Intent (I) | Capability (C) | Motivation (M) | Threat ranking |
|---|
Target attractiveness is assessed using the CARVERI model — Criticality, Accessibility, Recoverability, Vulnerability, Effect, Recognisability and Insider access.
Assess a scenario
Pick an asset and an undesired act. Severity, likelihood and the untreated risk rating calculate as you choose. Every field is a controlled selection so two assessors working the same scenario land on the same number.
Scenario definition
Risk treatment 0 selected
Treatment reduces vulnerability (deter, detect, delay), attractiveness (deter) and consequence (respond, recover) on a saturating curve — additional overlapping measures give diminishing returns, and no measure set drives residual risk below the retained baseline. Countermeasures only earn credit where they are functional and maintained as designed.
Security risk register
Ranked by untreated risk rating. Risks scoring 20.0 and above are reportable High Risks requiring explicit consideration in the security planning, design and operation of the development.
Summary
Register 0
| # | Security event type | Cat | Asset | C | V | A | H | S | L | R | Untreated | RR | Residual | Treatment |
|---|
Security risk matrix — untreated
Plotted by risk log number against integer severity and likelihood bands. Mitigation is sequenced top to bottom, red through green.
Security risk matrix — residual
Proposed security measures & mitigations
Generated from the treatment selected against every risk in the register, consolidated and de-duplicated, then prioritised by the highest untreated risk each measure treats. Each measure is mapped to the protection objectives it satisfies — Deter, Detect, Delay, Respond, Recover.
Protection objectives coverage
Residual risk statement
HCIS classification compliance —
Measures the applicable HCIS security directives require for the facility security classification declared in step 01. A gap here is a submission risk, not a scoring one — it does not change any risk rating.
Standards and regulatory basis 0
Every standard invoked by the proposed treatment, grouped by issuing authority. This is the compliance basis for the measures above and the evidence set a regulator will expect at submission.
HARISAGENT.AI