HARIS
STRA Security Threat & Risk Assessment ISO 31000:2018 · HB 167 · DDDRR treatment model
Step 01 — Establishing the context

Assessment scope & threat environment

Set the assessment boundary and the baseline threat picture. The country, local and target-attractiveness ratings entered here seed the default likelihood inputs on every risk line.

Document control

e.g. 01/06/2026

Scope of assessment

SEC-01 Appendix A — determines the applicable directives

Exclusions carried from the source methodology: health & safety hazards, financial risk, business impact analysis and business continuity planning are assessed separately. Cyber is limited to physical access control unless set to in-scope above.

Threat environment ratings avg —

Threat category ratings

Step 02 — Asset identification & criticality

Critical asset register

Assets are ranked 1–5 against the Impact Severity Criteria — human losses, national reputation, damage to property and disruption to operations. Selecting an asset type pre-loads its typical criticality; override it where the project context differs.

Add asset

Asset register 0

RefCategoryAssetZoneExposureCSeverity class
Step 03 — Threat identification & classification

Adversary characterisation

Each adversary is rated on intent, assumed capability and motivation. The threat ranking is the mean of the three, and feeds the historical-likelihood default for scenarios attributed to that adversary.

Adversary profiles

Adversary typeSourceIntent (I)Capability (C)Motivation (M)Threat ranking

Target attractiveness is assessed using the CARVERI model — Criticality, Accessibility, Recoverability, Vulnerability, Effect, Recognisability and Insider access.

Step 04 — Risk analysis

Assess a scenario

Pick an asset and an undesired act. Severity, likelihood and the untreated risk rating calculate as you choose. Every field is a controlled selection so two assessors working the same scenario land on the same number.

Criticality Cselect asset
Vulnerability V
Attractive A
Historical H
Severity S(C + V) ÷ 2
Likelihood L(A + H + V) ÷ 3
Untreated riskS × L
Residual riskapply treatment

Scenario definition

Add assets in step 02 first.

Risk treatment 0 selected

★ marks measures indicated for this scenario

Treatment reduces vulnerability (deter, detect, delay), attractiveness (deter) and consequence (respond, recover) on a saturating curve — additional overlapping measures give diminishing returns, and no measure set drives residual risk below the retained baseline. Countermeasures only earn credit where they are functional and maintained as designed.

Step 05 — Risk evaluation

Security risk register

Ranked by untreated risk rating. Risks scoring 20.0 and above are reportable High Risks requiring explicit consideration in the security planning, design and operation of the development.

Summary

Register 0

#Security event typeCatAsset CVAH SLRUntreated RRResidualTreatment

Security risk matrix — untreated

Plotted by risk log number against integer severity and likelihood bands. Mitigation is sequenced top to bottom, red through green.

Security risk matrix — residual

Step 06 — Protection objectives & treatment plan

Proposed security measures & mitigations

Generated from the treatment selected against every risk in the register, consolidated and de-duplicated, then prioritised by the highest untreated risk each measure treats. Each measure is mapped to the protection objectives it satisfies — Deter, Detect, Delay, Respond, Recover.

Protection objectives coverage

Residual risk statement

Standards and regulatory basis 0

Every standard invoked by the proposed treatment, grouped by issuing authority. This is the compliance basis for the measures above and the evidence set a regulator will expect at submission.

HARISAGENT.AI