Assessment workflow and risk scoring
The six canonical steps
Section titled “The six canonical steps”1. System decomposition
Section titled “1. System decomposition”Define components, capabilities, tools, goals, constraints, interactions and trust boundaries. Select the closest canonical architecture pattern.
2. Layer-specific threat modelling
Section titled “2. Layer-specific threat modelling”For each canonical threat:
- Confirm applicability.
- Describe the specific asset and path.
- Identify actors, prerequisites and vulnerabilities.
- State the credible consequence.
3. Cross-layer threat identification
Section titled “3. Cross-layer threat identification”Trace how a compromise can move between layers. Record entry point, intermediate transitions, final impact and independent break points.
4. Risk assessment
Section titled “4. Risk assessment”Score likelihood and impact from 1 to 5. State whether the scores represent inherent or residual risk.
5. Mitigation planning
Section titled “5. Mitigation planning”Define preventive, detective, response and recovery controls, accountable owner, target date, dependencies and acceptance authority.
6. Implementation and monitoring
Section titled “6. Implementation and monitoring”Validate controls through evidence and testing. Monitor changing threats, system behaviour, exceptions and architecture changes. Reassess continuously.
Likelihood scale
Section titled “Likelihood scale”| Score | Label | Practical anchor |
|---|---|---|
| 1 | Rare | Requires exceptional access or conditions; no credible recent path; strong controls tested |
| 2 | Unlikely | Feasible but constrained; limited exposure; several effective independent controls |
| 3 | Possible | Credible conditions exist; similar attacks occur; control coverage is mixed or partly tested |
| 4 | Likely | Exposed path, capable actor or frequent precursor; important controls are weak or untested |
| 5 | Almost certain | Active exploitation, repeated events or near misses; trivial path; controls absent or bypassed |
Likelihood should consider:
- External and internal exposure.
- Attacker access and capability.
- Frequency and opportunity.
- Known techniques and threat intelligence.
- Complexity and prerequisites.
- Strength and independence of preventive and detective controls.
- Test results and prior incidents.
- Change rate and time-to-detection.
Do not reduce likelihood merely because a policy exists.
Impact scale
Section titled “Impact scale”| Score | Label | Practical anchor |
|---|---|---|
| 1 | Negligible | Local, short-lived and easily reversible; no sensitive data or consequential decision |
| 2 | Minor | Limited operational or data effect; manageable recovery; low external consequence |
| 3 | Moderate | Material disruption, privacy issue, financial loss or affected individuals; containable |
| 4 | Major | Serious legal, customer, security, safety or business harm; broad or difficult recovery |
| 5 | Severe | Catastrophic, irreversible or systemic harm; critical infrastructure, life safety or fundamental rights |
Assess impact across:
- Confidentiality, integrity and availability.
- Privacy and fundamental rights.
- Safety and physical consequences.
- Financial loss and fraud.
- Legal, regulatory and contractual duties.
- Customer and public harm.
- Mission and operational continuity.
- Reputation and market integrity.
- Blast radius, persistence, detectability and reversibility.
Use the highest credible consequence, not an average of unrelated outcomes.
Risk calculation
Section titled “Risk calculation”Raw risk = likelihood × impact
| Raw product | Severity | Gamut band |
|---|---|---|
| 1–4 | 1 | Low |
| 5–9 | 2 | Moderate |
| 10–14 | 3 | Elevated |
| 15–19 | 4 | High |
| 20–25 | 5 | Critical |
Examples:
- Likelihood 2 × impact 4 = 8 → Moderate.
- Likelihood 3 × impact 4 = 12 → Elevated.
- Likelihood 4 × impact 5 = 20 → Critical.
Inherent versus residual risk
Section titled “Inherent versus residual risk”- Inherent risk assumes current controls have not yet reduced the threat.
- Residual risk considers controls only where their design and operation are evidenced.
Record which basis is being used. Do not mix inherent likelihood with residual impact or call a control-maturity score “risk”.
Roll-up rules
Section titled “Roll-up rules”Gamut uses maxima for MAESTRO roll-up:
- A section’s risk is its highest scored threat, not its average.
- A system’s posture is its highest scored threat.
- The workspace view reports the worst system and distribution of each assessed system’s worst-case band.
This prevents one Critical threat from being diluted by many Low threats.
Unscored threats do not count as Low. Coverage is displayed separately.
Treatment expectations by band
Section titled “Treatment expectations by band”| Band | Expected response |
|---|---|
| Low | Confirm baseline controls and monitor material change |
| Moderate | Document proportionate treatment, owner and review date |
| Elevated | Actively reduce risk and validate prevention, detection, response and recovery |
| High | Treat before broader deployment unless formally accepted by authorised risk ownership |
| Critical | Contain or pause the capability pending effective treatment or exceptional executive acceptance |
Scoring quality checks
Section titled “Scoring quality checks”Before accepting a score, confirm:
- The scenario names real components.
- Likelihood cites exposure and control evidence.
- Impact describes a credible outcome.
- The score basis is inherent or residual.
- Missing information has not been converted into a low score.
- A failed test or open finding is reflected.
- Cross-layer amplification is considered.
- The risk owner can understand and challenge the rationale.
When to rescore
Section titled “When to rescore”Rescore after:
- Control implementation or retesting.
- Model, data, tool, provider or architecture change.
- New vulnerability or threat intelligence.
- Incident, near miss or detected abuse.
- Increased autonomy or privilege.
- Deployment into a more sensitive environment.
- New regulatory or contractual exposure.
- Risk acceptance expiry.