Risk Domain Model

Explore the relationships between threats, hazards, opportunities, vulnerabilities, risk, assets, controls, governance, and people.

Interactive Risk Domain Model

Choose a domain or select any concept to reveal its definition and relationships.

Open full screen

Use the domain filters to focus the model. Select a concept to spotlight its connections; select it again, click the background, or press Escape to reset.

Understanding Risk Through A Domain Model

Risk is a connected system, not a list of isolated issues.

The risk domain model maps the deliberate threat-agent route and the unintentional hazard route into risk. Both can exploit vulnerabilities and cause events against assets. On the deliberate route, it distinguishes an asset's business value from the attack value perceived by an event agent: the first determines business criticality and impact, while the second shapes attacker criticality, motivation, target selection, and likelihood. Both perspectives inform proportionate risk treatment. The model also maps the upside of uncertainty through opportunities that can enhance business value.

How To Use It

  1. Start with an asset, the value it delivers, and the environment in which it operates.
  2. Explore deliberate threats through event agents, motivation, access opportunity, capability, perceived attack value, and specific events.
  3. Explore unintentional harm through hazards, triggers, exposure, and hazardous events.
  4. Explore positive outcomes through drivers, opportunities, appetite, and enhanced business value.
  5. Compare business criticality with attacker criticality, then trace how both inform risk treatment and control selection.
  6. Trace how vulnerabilities lead to risk and how controls, mechanisms, systems, and processes reduce it.
  7. Connect the model to appetite, thresholds, indicators, metrics, and maturity.

Model Domains

DomainWhat It Helps Explain
Governance & measurementHow appetite and the two criticality perspectives inform treatment, thresholds, indicators, metrics, and evidence of maturity.
Security Reference ModelHow policy and control objectives are realised through controls, mechanisms, systems, processes, and products.
Risk coreHow threats and hazards exploit vulnerabilities and lead to risk to an asset.
Asset & valueHow assets, processes, dependencies, environment, and business value determine business criticality and impact.
Opportunity modelHow drivers of change create opportunities that can enhance business value when pursued within appetite.
PeopleHow asset owners set appetite and authorise actors who work with assets and execute processes.
Hazard modelHow triggers and exposure turn unintentional hazards into hazardous events.
Threat agent modelHow motivation, access opportunity, capability, and perceived attack value enable agents to select targets, realise threats, and initiate events.

Supporting Downloads

Static editions of the model remain available for reading, workshops, and adaptation.