Understanding Risk Through A Domain Model
Risk is a connected system, not a list of isolated issues.
The risk domain model maps the deliberate threat-agent route and the unintentional hazard route into risk. Both can exploit vulnerabilities and cause events against assets. On the deliberate route, it distinguishes an asset's business value from the attack value perceived by an event agent: the first determines business criticality and impact, while the second shapes attacker criticality, motivation, target selection, and likelihood. Both perspectives inform proportionate risk treatment. The model also maps the upside of uncertainty through opportunities that can enhance business value.
How To Use It
- Start with an asset, the value it delivers, and the environment in which it operates.
- Explore deliberate threats through event agents, motivation, access opportunity, capability, perceived attack value, and specific events.
- Explore unintentional harm through hazards, triggers, exposure, and hazardous events.
- Explore positive outcomes through drivers, opportunities, appetite, and enhanced business value.
- Compare business criticality with attacker criticality, then trace how both inform risk treatment and control selection.
- Trace how vulnerabilities lead to risk and how controls, mechanisms, systems, and processes reduce it.
- Connect the model to appetite, thresholds, indicators, metrics, and maturity.