High School AdvancedModule A3Lesson 6 of 10Evidence-Aware Prioritization

A3.6 Risk Ranking in Threat Models

Learn how professional defenders compare fictional threat scenarios using defined impact, likelihood, exposure, control strength, uncertainty, confidence, mission context, dependency, and recovery criteria. Build priorities that are explainable and revisable without pretending that a score is an objective prediction.

Lesson Progress

Risk Ranking in Threat Models

High School AdvancedA3: Threat Modeling • Lesson 6 of 10

60% complete

Readiness Check

Before You Start

0/6 ready

Professional Hook

A Number Can Look Precise while Hiding Weak Reasoning

A fictional Northbridge reviewer assigns the supplier-result scenario a score of 19. The number appears exact, but the worksheet does not define its scale, show how delay and stale state affect mission impact, explain whether queue controls operate, record uncertainty about source health, or identify the risk owner. Another reviewer gives the same scenario a score of 8. Neither number is useful until the team agrees on criteria and documents evidence.

Weak ranking

“Risk score: 19, Critical.” No scenario definition, scale, evidence, controls, uncertainty, owner, disagreement, recovery, or review trigger is shown.

Strong ranking

“Residual risk: High, with moderate confidence. Impact is High because stale case state can affect decisions and users; likelihood is Moderate based on one exercise and incomplete current-state evidence; control effectiveness is only partially demonstrated.”

The goal is not to create the most impressive score. The goal is to help authorized fictional owners decide what needs evidence, mitigation, monitoring, recovery preparation, acceptance, or review first.

Exactly Five Learning Objectives

What You Will Be Able to Do

Objective 1

Explain fictional risk ranking as a structured decision process that compares evidence, impact, likelihood, exposure, control strength, uncertainty, mission context, and recovery—not as an objective prediction.

Objective 2

Define consistent fictional ranking scales and criteria for impact, likelihood, exposure, control effectiveness, confidence, uncertainty, and residual risk.

Objective 3

Evaluate fictional threat scenarios without confusing threat category, possibility, severity, actor intent, exploitability, or missing evidence.

Objective 4

Document fictional ranking rationale, evidence, assumptions, unknowns, disagreements, owners, review triggers, and confidence so that priorities remain explainable and revisable.

Objective 5

Create a portfolio-ready fictional threat-risk register that remains ethical, defensive, non-operational, privacy-safe, evidence-aware, and completely invented.

Why This Matters

Prioritization Directs Limited Defensive Time and Resources

Fictional teams cannot improve every concern at the same time. Risk ranking helps them compare scenarios, decide where evidence is missing, identify the most important mitigations, schedule reviews, prepare recovery, communicate uncertainty, and assign accountable owners. Poor ranking can waste effort, hide human impact, or create false confidence.

Impact question

What fictional mission, user, data, identity, privacy, service, evidence, recovery, safety, or trust harm could result?

Likelihood question

How plausible is the fictional scenario under current preconditions, exposure, actor opportunity, controls, change, history, and recovery?

Decision question

Which owner should gather evidence, reduce risk, monitor, accept residual exposure, escalate, or review the scenario?

Core Framework

The R-A-N-K-E-D Method

R — Refine the scenario

Confirm one fictional scenario, affected assets, actor context, state, category, scope, evidence, and owners.

A — Assess impact

Review mission, data, privacy, identity, availability, safety, evidence, recovery, user, and trust consequences.

N — Note likelihood and exposure

Evaluate preconditions, opportunity, reachability, frequency, change, complexity, detectability, and dependencies.

K — Know the controls

Distinguish controls that are proposed, designed, implemented, operating, monitored, reviewed, and resilient.

E — Explain uncertainty

Record assumptions, unknowns, stale evidence, conflict, confidence, and decision-blocking gaps.

D — Decide and document

Assign inherent and residual bands, priority, urgency, treatment, owners, review dates, and triggers.

Decision-ready risk statement

This fictional scenario has a documented inherent and residual risk band based on defined impact, likelihood, exposure, control, uncertainty, mission, and recovery criteria. The ranking cites evidence and limits, records owner disagreement, states confidence, explains the next action, and identifies review triggers. It does not claim that harm will occur.

Advanced Vocabulary

Terms for Evidence-Aware Risk Ranking

Risk ranking

A structured fictional comparison of threat scenarios using defined criteria so owners can decide what requires attention first.

Impact

The fictional degree of harm to mission, people, data, identity, privacy, service, evidence, safety, recovery, trust, or organizational responsibility if a scenario occurs.

Likelihood

A reasoned fictional estimate of how plausible a scenario is under current assumptions, exposure, actor opportunity, control state, history, and evidence.

Exposure

The fictional degree to which an asset, actor relationship, entry point, flow, boundary, dependency, or capability is reachable, shared, privileged, externally dependent, or difficult to observe.

Control strength

The fictional degree to which safeguards are appropriately designed, implemented, operating, monitored, reviewed, and able to fail safely.

Control coverage

The fictional extent to which prevention, detection, response, recovery, privacy, governance, communication, and source-health controls address a scenario.

Uncertainty

The fictional degree to which missing evidence, stale records, assumptions, conflicting sources, unknown ownership, or incomplete scope limits confidence.

Confidence

A documented fictional judgment about how strongly the available evidence supports the ranking.

Inherent risk

A fictional view of risk before considering the expected effect of current controls.

Residual risk

A fictional view of the risk that remains after considering current controls, limitations, dependencies, uncertainty, and recovery.

Risk owner

The fictional role authorized to decide whether residual risk is accepted, reduced, transferred, avoided, monitored, or escalated.

Scenario owner

The fictional role responsible for validating the threat scenario, maintaining evidence, coordinating mitigations, and reviewing changes.

Risk criterion

A defined fictional factor used consistently across scenarios, such as impact, likelihood, exposure, control strength, uncertainty, recovery, or mission dependence.

Ordinal scale

A fictional ordered set of labels such as Low, Moderate, High, and Very High where the order matters more than exact numerical distance.

False precision

Presenting fictional scores or percentages as more exact, objective, or predictive than the evidence supports.

Risk matrix

A fictional comparison tool that combines defined impact and likelihood bands while preserving evidence, uncertainty, and context.

Risk appetite

A fictional organization's general willingness to accept different kinds and levels of risk while pursuing its mission.

Risk tolerance

A fictional boundary around how much variation, delay, exposure, uncertainty, or residual harm is acceptable for a specific objective.

Priority

The fictional order in which scenarios should receive owner attention, evidence collection, mitigation, monitoring, or review.

Urgency

The fictional time sensitivity of a decision based on exposure, active change, control gap, dependency, deadline, or possible impact.

Velocity

The fictional speed at which harm could develop after a scenario begins.

Recoverability

The fictional ability to restore correct technical and business state, authority, evidence, communication, and trust within acceptable time.

Risk rationale

The fictional explanation that connects scenario, criteria, evidence, assumptions, controls, uncertainty, owners, and the resulting priority.

Risk review trigger

A fictional change or event that requires the ranking to be reconsidered, such as a new supplier, control change, incident lesson, evidence gap, ownership change, or recovery result.

Instructional Section 1

Apply Ten Ranking Principles

Rank scenarios, not vague topics

Evaluate a specific fictional actor–action–asset–condition–outcome scenario rather than assigning one score to an entire system, role, supplier, or category.

Strong practice

Rank “delayed supplier results update stale case state when reconciliation is incomplete,” not “supplier risk.”

If ignored

Vague objects hide different impacts, controls, owners, evidence, and recovery needs.

Define scales before scoring

Publish fictional criteria and examples for every impact, likelihood, exposure, control, uncertainty, and confidence band.

Strong practice

Reviewers use the same definitions and record why a scenario fits a band.

If ignored

Teams may use the same label to mean very different things.

Use evidence and preserve limits

Connect each fictional rating to supplied records, owner decisions, diagrams, exercises, events, tickets, reviews, and source-health information.

Strong practice

State what evidence supports, what it does not prove, and when it was reviewed.

If ignored

Plausibility, familiarity, fear, or confidence can replace evidence.

Separate category from severity

Identity, privacy, integrity, availability, governance, or resilience labels describe concern type—not importance.

Strong practice

Apply the same risk criteria across all relevant category families.

If ignored

Teams may automatically over-rank some categories and under-rank others.

Separate likelihood from impact

A highly harmful fictional outcome may be unlikely, while a frequent condition may have limited impact.

Strong practice

Score and explain both dimensions independently before combining them.

If ignored

One dramatic consequence can dominate the entire ranking.

Include control effectiveness

Consider whether fictional controls are designed, implemented, operating, monitored, reviewed, and resilient.

Strong practice

Record control evidence and limitations rather than assuming a listed control works.

If ignored

A control inventory can create false confidence.

Treat uncertainty as information

Missing ownership, incomplete fields, stale reviews, conflicting sources, or unhealthy evidence should affect confidence and follow-up.

Strong practice

Record uncertainty separately and assign an evidence owner.

If ignored

Unknowns are silently converted into low or high risk without explanation.

Consider mission and human context

Evaluate fictional user, service, privacy, safety, fairness, communication, recovery, and trust outcomes—not only technical effects.

Strong practice

Use mission owners and affected-user perspectives in impact review.

If ignored

Technical availability may be treated as success while business or human state remains unsafe.

Document disagreement

Preserve fictional differences between security, privacy, operations, data, supplier, recovery, support, and mission owners.

Strong practice

Record each rationale, evidence, uncertainty, and final decision owner.

If ignored

A forced consensus can hide meaningful assumptions and tradeoffs.

Review rankings when context changes

Update fictional priorities when assets, actors, interfaces, flows, suppliers, controls, automation, evidence, recovery, or ownership changes.

Strong practice

Use dates, triggers, versions, and named owners.

If ignored

A once-useful score can become a stale source of false confidence.

Instructional Section 2

Assess Eight Impact Dimensions

Fictional impact should be reviewed across multiple dimensions. The strongest dimension may guide the final impact band, but the rationale should preserve all meaningful harms and owner perspectives.

Mission and service outcome

Low

Minor fictional inconvenience with a supported workaround and no meaningful interruption to the service objective.

Moderate

Noticeable delay or reduced quality affecting a limited group or workflow.

High

Major disruption, incorrect decision, or loss of a critical service outcome.

Very High

Severe fictional failure of an essential mission, widespread service, or high-consequence decision process.

Supporting fictional evidence

Service objectives, business-impact notes, user journeys, support themes, leadership decisions, and recovery exercises.

Data and integrity

Low

Small, easily corrected fictional record issue with strong detection and reconciliation.

Moderate

Limited incorrect, missing, delayed, duplicated, or stale data requiring owner review.

High

Significant fictional workflow, decision, evidence, or record integrity impact across multiple users or services.

Very High

Widespread or difficult-to-recover fictional corruption of critical data, decisions, evidence, or business state.

Supporting fictional evidence

Validation results, reconciliation, event order, change history, duplicate handling, source health, and data-owner review.

Confidentiality and privacy

Low

Minimal fictional exposure of low-sensitivity information to a narrowly limited audience with rapid correction.

Moderate

Limited disclosure, over-collection, inappropriate purpose, or retention involving sensitive context.

High

Substantial fictional exposure, misuse, inference, audience expansion, or retention affecting important personal or organizational data.

Very High

Widespread, highly sensitive, or difficult-to-remediate fictional privacy or confidentiality harm.

Supporting fictional evidence

Data classification, field inventory, approved purpose, audience, sharing records, access, retention, deletion, and privacy review.

Identity and authority

Low

Narrow fictional authority issue with limited action scope and strong review.

Moderate

Role, assignment, object, approval, or lifecycle weakness affecting a limited set of actions.

High

Broad or privileged fictional authority that can affect sensitive assets, users, configuration, workflow, or recovery.

Very High

Concentrated fictional authority across critical identity, data, service, evidence, and recovery assets with weak separation or review.

Supporting fictional evidence

Role maps, object checks, approvals, access reviews, administrative events, lifecycle, and emergency-access records.

Availability and dependency

Low

Brief fictional delay with limited user effect and a tested alternate path.

Moderate

Service degradation or dependency failure affecting a defined workflow or group.

High

Sustained fictional outage, hidden backlog, significant delay, or shared dependency failure affecting major services.

Very High

Widespread fictional inability to provide essential service or recover within mission needs.

Supporting fictional evidence

Health, queues, capacity, service objectives, dependency maps, supplier records, support impact, and recovery exercises.

Safety and human impact

Low

Minor fictional confusion or inconvenience with clear correction and no significant decision consequence.

Moderate

Meaningful delay, confusion, accessibility barrier, or decision-quality effect for some users.

High

Serious fictional harm to service access, fairness, trusted decisions, communication, or vulnerable users.

Very High

Severe fictional harm to people, essential support, safety, rights, or high-consequence decisions.

Supporting fictional evidence

User journeys, support records, complaints, communications, decision reviews, accessibility review, and mission-owner input.

Evidence and accountability

Low

Limited fictional evidence gap with alternative reliable records and low decision impact.

Moderate

Missing context or source-health uncertainty that slows review or weakens confidence.

High

Major fictional inability to attribute actions, validate state, investigate, recover, or support required decisions.

Very High

Widespread fictional loss of trustworthy evidence across critical identity, workflow, recovery, or governance decisions.

Supporting fictional evidence

Event schemas, source health, correlation, tickets, approvals, timestamps, retention, access, and review quality.

Recovery and trust

Low

Fictional state can be restored quickly with tested evidence and little user impact.

Moderate

Recovery requires manual work, additional validation, or limited communication repair.

High

Recovery is slow, dependent, uncertain, or likely to leave stale, duplicated, or incorrect business state.

Very High

Fictional recovery cannot reliably restore critical service, authority, data, evidence, communication, or trust.

Supporting fictional evidence

Restore tests, dependency order, recovery identity, configuration baselines, reconciliation, communications, closure, and lessons learned.

Instructional Section 3

Evaluate Eight Likelihood and Exposure Factors

Required preconditions

Lower likelihood or exposure

Many independent fictional conditions must align and current evidence shows strong barriers.

Higher likelihood or exposure

Few conditions are required, or one common workflow state may be enough.

Evidence

Abuse-case preconditions, control design, role scope, workflow state, supplier dependency, and review results.

Actor opportunity

Lower likelihood or exposure

Narrow fictional role, uncommon workflow, limited object set, short time window, and strong approval.

Higher likelihood or exposure

Broad role, frequent workflow, shared interface, long-lived access, or common service identity.

Evidence

Actor inventory, role map, assignment, frequency, lifecycle, interface use, and approval records.

Exposure

Lower likelihood or exposure

Limited fictional reachability, constrained interface, isolated environment, restricted audience, and strong ownership.

Higher likelihood or exposure

Public, shared, supplier-dependent, privileged, broadly reachable, or difficult-to-observe relationship.

Evidence

Entry-point inventory, trust boundaries, network zones, supplier relationships, user population, and interface ownership.

Control reliability

Lower likelihood or exposure

Fictional controls are specifically designed, operating, monitored, tested, reviewed, and fail safely.

Higher likelihood or exposure

Controls are missing, generic, untested, stale, inconsistently applied, or unsupported by evidence.

Evidence

Control requirements, test results, monitoring, reviews, exceptions, source health, and failure exercises.

Historical and exercise evidence

Lower likelihood or exposure

No similar fictional events in a relevant period, with healthy evidence and strong control review.

Higher likelihood or exposure

Repeated fictional tickets, exercises, failures, or near misses show similar conditions.

Evidence

Tickets, incident summaries, exercises, alert reviews, support patterns, and change history.

Change and complexity

Lower likelihood or exposure

Stable fictional design, limited dependencies, clear ownership, controlled release, and current documentation.

Higher likelihood or exposure

Recent change, multiple suppliers, complex state, many handoffs, temporary interfaces, or unclear ownership.

Evidence

Change requests, architecture versions, dependency maps, owner records, release evidence, and temporary-access records.

Detectability before harm

Lower likelihood or exposure

Fictional evidence reliably identifies unsafe state early enough for intervention.

Higher likelihood or exposure

Evidence is delayed, ambiguous, unhealthy, incomplete, or available only after business impact.

Evidence

Event meaning, source health, alert thresholds, correlation, dashboard review, and response timing.

Recovery difficulty

Lower likelihood or exposure

Fictional restoration and reconciliation are tested, timely, and supported by trusted evidence.

Higher likelihood or exposure

Recovery depends on stale identities, uncertain state, manual repair, supplier coordination, or incomplete reconciliation.

Evidence

Recovery tests, dependency order, identity records, reconciliation, communication, and closure review.

Instructional Section 4

Assess Controls by Evidence Maturity

A fictional policy, tool, diagram, or requirement should not reduce residual risk merely because it exists on paper. Review control evidence in stages.

Not demonstrated

The fictional control may be proposed, assumed, undocumented, unowned, or unsupported by evidence.

Fictional evidence

No current design decision, implementation evidence, operating result, monitoring, test, or owner confirmation.

Ranking effect

Do not count the control as reducing residual risk. Increase uncertainty and assign an evidence owner.

Designed

The fictional control has a documented purpose, owner, scope, and expected behavior.

Fictional evidence

Design record, policy, architecture decision, role definition, workflow, or requirement.

Ranking effect

Recognize design intent but do not assume implementation or operating effectiveness.

Implemented

The fictional control is represented in configuration, workflow, process, or deployed design evidence.

Fictional evidence

Approved configuration summary, workflow record, deployment evidence, role mapping, or interface decision.

Ranking effect

Consider partial risk reduction while preserving uncertainty about actual operation.

Operating

The fictional control produces expected outcomes and evidence under normal and relevant failure conditions.

Fictional evidence

Event output, test result, review sample, source health, ticket analysis, or exercise outcome.

Ranking effect

Consider stronger reduction when evidence is current, relevant, and complete.

Monitored and reviewed

The fictional control has health, ownership, exception, performance, failure, and review evidence.

Fictional evidence

Metrics, source-health dashboard, access review, control test, exception log, and owner sign-off.

Ranking effect

Use the strongest justified reduction while documenting limitations, dependencies, and residual risk.

Resilient and recoverable

The fictional control continues or fails safely during disruption and supports recovery and reconciliation.

Fictional evidence

Failure test, alternate path, recovery exercise, integrity validation, communication, and closure review.

Ranking effect

Account for reduced impact or likelihood only where recovery evidence supports the claim.

Instructional Section 5

Make Uncertainty Visible

Low uncertainty

Fictional scope, owners, evidence, control state, affected assets, and scenario conditions are current and consistent.

Recommended action

Proceed with ranking while retaining normal review triggers.

Moderate uncertainty

Some fictional assumptions, evidence sources, owner decisions, or control details remain incomplete but the central scenario is understandable.

Recommended action

Rank with caution, document confidence, and assign targeted evidence actions.

High uncertainty

Important fictional ownership, exposure, data, identity, control, event, source-health, or recovery information is missing or conflicting.

Recommended action

Avoid false precision, consider a provisional priority, and escalate evidence collection.

Decision-blocking uncertainty

The fictional scenario, affected assets, current state, control state, or business context is too unclear for a responsible ranking.

Recommended action

Pause final ranking, preserve the concern, assign owners, and define the evidence needed to continue.

Uncertainty is not the same as risk. It affects confidence, evidence actions, urgency, and decision quality. It should never be silently converted into Low or Very High without explanation.

Instructional Section 6

Use Four Fictional Risk Bands

Low

The fictional scenario has limited impact and likelihood, strong controls, high recoverability, and low uncertainty.

Typical response

Maintain controls, document rationale, monitor changes, and review on schedule.

Important warning

Low does not mean impossible or irrelevant; it means lower priority under current evidence and criteria.

Moderate

The fictional scenario has meaningful but bounded impact or likelihood, partial control coverage, manageable recovery, or moderate uncertainty.

Typical response

Assign an owner, plan proportionate improvement, collect missing evidence, and monitor review triggers.

Important warning

Moderate scenarios can become urgent when context, exposure, control state, or dependencies change.

High

The fictional scenario can significantly affect mission, people, privacy, integrity, service, evidence, authority, or recovery and has credible conditions or weak control coverage.

Typical response

Prioritize owner review, evidence validation, mitigation planning, monitoring, recovery preparation, and leadership visibility.

Important warning

High is not proof that harm will occur; it is a decision priority supported by defined criteria.

Very High

The fictional scenario combines severe impact, credible conditions, broad exposure, weak controls, difficult recovery, concentrated dependency, or major uncertainty requiring immediate owner attention.

Typical response

Escalate to authorized leadership and owners, define near-term protective action, preserve evidence, and review residual risk frequently.

Important warning

Very High should be rare, evidence-aware, and justified—not used as a dramatic label.

Professional Workflow

Ten Steps from Scenario to Maintained Risk Decision

1

Confirm the scenario

Use one fictional abuse case with defined actor context, assets, preconditions, capability, outcome, evidence, controls, owners, and state.

Required output

Stable scenario identifier and decision statement.

Quality check

The scenario is specific enough that different reviewers are ranking the same thing.

2

Verify scope and category

Confirm current or future state, affected environment, trust boundary, primary category, meaningful secondary categories, and exclusions.

Required output

Scope and category record.

Quality check

Category labels organize the scenario but do not determine severity.

3

Rate impact dimensions

Review mission, data, privacy, identity, availability, safety, evidence, recovery, and trust impacts.

Required output

Impact table with rationale, evidence, owner input, and strongest dimension.

Quality check

Impact is bounded and does not rely on catastrophic language.

4

Rate likelihood factors

Review preconditions, opportunity, exposure, control reliability, history, change, detectability, and recovery difficulty.

Required output

Likelihood table with evidence and assumptions.

Quality check

Likelihood is not inferred from impact or category.

5

Assess control strength

Determine whether each fictional control is merely proposed, designed, implemented, operating, monitored, reviewed, and resilient.

Required output

Control-evidence matrix with limitations and owners.

Quality check

A listed control is not counted as effective without supporting evidence.

6

Record uncertainty and confidence

Identify missing ownership, stale records, conflicting evidence, source-health gaps, incomplete scope, or untested recovery.

Required output

Uncertainty level, confidence statement, and evidence action list.

Quality check

Unknowns remain visible rather than being converted into a score.

7

Assign inherent and residual bands

Use defined fictional criteria to compare risk before and after control evidence.

Required output

Inherent band, residual band, rationale, and disagreement record.

Quality check

The result explains how controls and uncertainty changed the decision.

8

Set priority and urgency

Consider mission deadlines, active change, exposure, dependencies, review dates, recovery, and owner capacity.

Required output

Priority order, urgency, owner, and next decision date.

Quality check

Priority is not based only on the final band.

9

Choose the decision path

Decide whether to reduce, avoid, transfer, accept, monitor, gather evidence, or escalate the fictional risk.

Required output

Risk treatment decision and residual-risk owner.

Quality check

The decision is authorized and tied to specific conditions and evidence.

10

Maintain the ranking

Set review triggers for changes in assets, identity, flows, suppliers, controls, evidence, incidents, recovery, ownership, or mission.

Required output

Version, review date, triggers, history, and retirement criteria.

Quality check

The ranking can be revised when context changes.

Worked Fictional Examples

Compare Risk Rationales without False Precision

Fictional supplier result updates stale case state after a queue delay.

Impact

High integrity and service impact because incorrect case status can affect decisions, communication, duplicate action, and trust.

Likelihood

Moderate because a similar delay occurred in a fictional exercise, but final production behavior and current controls remain uncertain.

Control evidence

Schema validation is designed; source-health reporting operates; state reconciliation and duplicate handling are not fully evidenced.

Uncertainty

Moderate to high because queue-health meaning, ordering, reconciliation, and current owner evidence are incomplete.

Inherent risk

High

Residual risk

High

Ranking rationale

Existing evidence does not justify enough reduction. The scenario deserves priority owner review and mitigation planning.

Fictional free-text support note may be sent to the processing supplier.

Impact

Moderate to high privacy and confidentiality impact depending on content, population, access, retention, and purpose.

Likelihood

Unclear because the field inventory shows the field exists but does not prove it is populated in current requests.

Control evidence

Data minimization is expected, but owner approval, field validation, supplier retention, and evidence are incomplete.

Uncertainty

High

Inherent risk

High

Residual risk

Provisional Moderate or High pending evidence

Ranking rationale

Final ranking should remain provisional because current use and control state are not sufficiently established.

Fictional archival service identity has no confirmed owner and an expired review.

Impact

Potentially high identity, governance, retention, recovery, and evidence impact because the service may affect archival state.

Likelihood

Moderate based on current active status and lifecycle gap, but misuse or excessive permission is not proven.

Control evidence

Service identity exists and activity may be logged, but ownership, access review, permission scope, and retirement are not confirmed.

Uncertainty

High

Inherent risk

High

Residual risk

High provisional

Ranking rationale

Ownership and authority evidence are needed before a more precise residual ranking.

Fictional notification-change tickets lack reason and user-confirmation fields.

Impact

Moderate because incorrect preferences can affect privacy, communication, workflow, user trust, and support effort.

Likelihood

Moderate because multiple fictional tickets show the evidence gap, but authorization or harmful outcomes are not proven.

Control evidence

Support role and tickets exist; verification, confirmation, event correlation, and review coverage are incomplete.

Uncertainty

Moderate

Inherent risk

Moderate

Residual risk

Moderate

Ranking rationale

The scenario warrants workflow and evidence improvement but does not justify an extreme rating.

Fictional recovery restores application service before notification and archival dependencies are validated.

Impact

High resilience, integrity, availability, safety, and trust impact because technical availability can return with incorrect business state.

Likelihood

Moderate because the condition occurred in one fictional exercise and dependencies remain complex.

Control evidence

Recovery plan and backups exist, but ordering, identity validation, reconciliation, communication, and closure evidence are incomplete.

Uncertainty

Moderate

Inherent risk

High

Residual risk

High

Ranking rationale

Recovery evidence supports a meaningful priority even though future frequency is unknown.

Fictional future analytics process may combine portal, support, supplier, and notification events.

Impact

Potentially high privacy, confidentiality, governance, accountability, and interpretation impact.

Likelihood

Not yet applicable as current exposure because the process is proposed future state.

Control evidence

Purpose, fields, audience, retention, access, owner, review, and safeguards are not yet approved.

Uncertainty

Decision-blocking for current-state risk ranking.

Inherent risk

Future-state High potential

Residual risk

Not yet assigned

Ranking rationale

Treat as a design decision and pre-implementation requirement, not as a current incident or deployed risk.

Fictional Risk Matrix

Northbridge Threat-Model Ranking View

This conceptual matrix is fully invented. It shows how impact and likelihood may support comparison, but it does not replace control, uncertainty, mission, owner, urgency, or recovery analysis.

Likelihood ↓ / Impact →LowModerateHighVery High
Very HighModerateHighVery HighVery High
HighModerateHighHighVery High
ModerateLowModerateHighHigh
LowLowLowModerateHigh
The matrix is only a starting point. A final fictional residual rating must also explain exposure, control evidence, uncertainty, dependency, mission importance, urgency, recovery, owner judgment, and review triggers.

Fake Dashboard

Fake Northbridge Threat-Risk Dashboard

Fictional scenario ranking, control evidence, uncertainty, and ownership status for training only.

Scenarios ready for final ranking

11 / 18

Seven scenarios still lack sufficient ownership, control, exposure, current-state, or recovery evidence.

High residual risks

4

Supplier-result integrity, archival identity governance, recovery sequencing, and temporary-interface ownership require prioritized review.

Decision-blocking uncertainty

2

The proposed analytics process and unclear free-text supplier field need owner decisions before final ranking.

Fake SOC Alert

Risk Score Uses Undefined Criteria

Source: Fake Northbridge Risk Governance Console • Time: 2:14 PM

High Severity
A fictional reviewer assigned numerical scores to all eighteen scenarios, but the worksheet does not define impact bands, likelihood bands, control maturity, uncertainty, confidence, or how current-state and future-state scenarios differ.
Defensive recommendation: Pause use of the scores. Publish the fictional ranking method, preserve the original reviewer rationale, reassess scenario readiness, document evidence and uncertainty, and assign authorized owners before final prioritization.

Fake Log Panel

Fake Risk-Ranking Review Timeline

training-log-viewer.log
09:00 METHOD impact-bands='defined' likelihood-bands='defined'
09:08 METHOD controls='designed,implemented,operating,reviewed'
09:16 METHOD uncertainty='low,moderate,high,blocking'
09:24 SCENARIO supplier-result readiness='ready'
09:32 IMPACT supplier-result='high' rationale='stale-case-state'
09:40 LIKELIHOOD supplier-result='moderate' evidence='exercise+gaps'
09:48 CONTROL supplier-result='partial' reconciliation='not-evidenced'
09:56 RESIDUAL supplier-result='high' confidence='moderate'
10:04 SCENARIO supplier-note readiness='provisional'
10:12 UNCERTAINTY supplier-note='high' current-use='unknown'
10:20 SCENARIO analytics readiness='blocked' state='future'
10:28 SCENARIO archive-identity residual='high-provisional'
10:36 SCENARIO notification-change residual='moderate'
10:44 SCENARIO recovery-sequence residual='high'
10:52 QUALITY false-precision='detected' numeric-scores='paused'
11:00 OWNER risk-decisions='assigned'
11:08 REVIEW privacy='complete' operations='complete'
11:16 REVIEW mission='pending' recovery='complete'
11:24 CONFIDENCE register='medium'
14:14 ALERT method='undefined-numeric-score'

Training note: this is fake data for defensive analysis practice only.

Fictional Evidence Matrix

What the Evidence Supports—and What It Does Not Prove

RR-01

Fictional queue-health dashboard

Observation

Processing-result events were delayed for twenty-two minutes while the source-health indicator remained Green.

Supports

Availability, integrity, accountability, dependency, and resilience criteria require review.

Does not prove

The dashboard does not prove data loss, malicious activity, incorrect final state, or future frequency.

Ranking use

Increase evidence attention and uncertainty; do not automatically assign Very High severity.

RR-02

Fictional support-ticket pattern

Observation

Users submitted duplicate records after delayed status notifications.

Supports

User, workflow, service, support, integrity, and communication impact may be meaningful.

Does not prove

The pattern does not prove one cause or that every duplicate produced the same impact.

Ranking use

Use as bounded impact evidence and preserve causal uncertainty.

RR-03

Fictional supplier-field inventory

Observation

The processing request may include a free-text support note.

Supports

Privacy and confidentiality impact could be meaningful if the field is populated, unnecessary, retained, or broadly accessed.

Does not prove

Current population, purpose, access, retention, and approval are not established.

Ranking use

Treat residual ranking as provisional and assign evidence actions.

RR-04

Fictional service-identity review

Observation

An archival service identity is active, lacks a confirmed owner, and is past its review date.

Supports

Exposure, governance, identity, authority, retention, and recovery uncertainty are elevated.

Does not prove

The record does not prove compromise, misuse, broad permission, or harmful activity.

Ranking use

Increase uncertainty and owner urgency without claiming an incident.

RR-05

Fictional recovery exercise

Observation

Application service returned before notification and archival dependencies were validated, producing stale messages and repeated tasks.

Supports

High potential impact and credible recovery complexity are supported by exercise evidence.

Does not prove

One exercise does not establish production frequency or prove all current controls are ineffective.

Ranking use

Support a meaningful resilience priority while preserving likelihood uncertainty.

RR-06

Fictional notification-ticket review

Observation

Several preference changes lack a recorded reason and user confirmation.

Supports

Accountability and workflow evidence are incomplete across multiple records.

Does not prove

The evidence does not prove unauthorized action, incorrect preference, intent, or user harm.

Ranking use

Support a Moderate evidence and process priority rather than a dramatic rating.

RR-07

Fictional analytics proposal

Observation

A proposed process may combine several event sources, but purpose, fields, audience, retention, and ownership remain unresolved.

Supports

Potential future privacy, confidentiality, governance, and interpretation impact requires design review.

Does not prove

The proposal is not proof of current collection, use, exposure, or control failure.

Ranking use

Record future-state potential and block final current-state ranking.

RR-08

Fictional temporary-interface inventory

Observation

A migration-import channel remains documented as enabled without confirmed current purpose, owner, activity, or retirement.

Supports

Exposure, ownership, lifecycle, identity, evidence, and dependency uncertainty are meaningful.

Does not prove

The inventory does not prove reachability, use, unsafe configuration, or malicious activity.

Ranking use

Assign a governance and evidence priority while avoiding unsupported severity.

Analyze the Evidence

Which Risk Decision Is Best Supported?

Processing-result events were delayed for twenty-two minutes while source health remained Green.
Users submitted duplicate documents after delayed status notifications.
The support tickets do not prove one technical cause.
A recovery exercise produced stale messages and repeated archival tasks after application restoration.
State reconciliation, duplicate handling, ordering, delay thresholds, and source-health meaning are not fully evidenced.
Schema validation is documented as designed, but operating and resilient evidence is incomplete.
The scenario affects case-state integrity, user communication, service quality, support workload, evidence, and recovery.
The fictional model has moderate confidence.

Which conclusion most responsibly ranks the fictional supplier-result scenario?

Common Mistakes

Errors That Weaken Risk Ranking

Using category as severity

Why it fails

A privacy, identity, supplier, or availability label does not determine importance.

Strong correction

Apply the same fictional impact, likelihood, exposure, control, uncertainty, mission, and recovery criteria across scenarios.

Multiplying numbers without explaining them

Why it fails

A mathematical-looking score can hide subjective definitions and false precision.

Strong correction

Publish criteria, show rationale, preserve evidence, and use numbers only as a support—not a substitute—for judgment.

Letting impact determine likelihood

Why it fails

A severe outcome may be rare, while a common condition may be low impact.

Strong correction

Rate impact and likelihood independently before combining them.

Treating missing evidence as Low

Why it fails

Unknown control state, ownership, exposure, or event history does not prove low risk.

Strong correction

Record uncertainty separately and assign an evidence action.

Treating missing evidence as automatically Very High

Why it fails

Uncertainty can justify urgency and caution, but it does not prove severe impact or likely occurrence.

Strong correction

Use provisional ratings, confidence statements, and decision-blocking labels when needed.

Assuming listed controls are effective

Why it fails

A policy, tool, dashboard, or design record may not prove implementation, operation, review, or resilience.

Strong correction

Assess control design, implementation, operation, monitoring, review, failure, and recovery evidence.

Ranking the entire system

Why it fails

One overall score hides different assets, scenarios, owners, controls, evidence, and priorities.

Strong correction

Rank specific fictional scenarios and aggregate only for communication with clear limits.

Ignoring user and mission impact

Why it fails

Technical measures may overlook service access, fairness, communication, privacy, trust, or decision consequences.

Strong correction

Include mission and affected-user perspectives in impact review.

Hiding disagreement

Why it fails

Different fictional owners may reasonably interpret evidence and impact differently.

Strong correction

Record viewpoints, assumptions, evidence, uncertainty, and the authorized final decision.

Using real risk registers

Why it fails

Real scenarios, controls, owners, suppliers, systems, incidents, recovery details, and priorities can be sensitive.

Strong correction

Invent every organization, asset, actor, scenario, score, record, control, owner, date, decision, and outcome.

Safe Fictional Practice Lab

Build the Northbridge Threat-Risk Register

Use only the supplied fictional information on this page. Do not access, scan, test, configure, investigate, monitor, recover, or change any real system. Do not use real incidents, risk registers, identities, suppliers, diagrams, logs, controls, recovery details, owners, or organizational priorities.
1

Publish the ranking method

Define fictional impact, likelihood, exposure, control strength, uncertainty, confidence, inherent risk, residual risk, and review bands before rating scenarios.

Required output

A ranking guide with clear criteria and examples.

Quality check

Two reviewers can explain the same bands even if they reach different evidence-based judgments.

2

Select scenario-ready cases

Choose fictional abuse cases with stable scope, assets, owners, evidence, controls, category, and current or future-state labels.

Required output

A risk-ranking queue with readiness status.

Quality check

Decision-blocking cases remain visible but are not forced into final ratings.

3

Assess impact

Review mission, data, privacy, identity, availability, safety, evidence, recovery, and trust dimensions.

Required output

Impact rationale with owner perspectives and strongest dimensions.

Quality check

The impact statement is bounded, fictional, and supported by evidence.

4

Assess likelihood and exposure

Review preconditions, actor opportunity, reachability, frequency, change, complexity, history, detectability, and recovery difficulty.

Required output

Likelihood and exposure rationale with assumptions.

Quality check

Likelihood is not copied from impact or category.

5

Assess controls

Record whether each fictional control is designed, implemented, operating, monitored, reviewed, and resilient.

Required output

Control-evidence table with limitations and owners.

Quality check

Only supported control effects reduce residual risk.

6

Record uncertainty and confidence

Identify missing, stale, conflicting, unhealthy, proposed, or unowned evidence.

Required output

Uncertainty level, confidence statement, and evidence plan.

Quality check

Unknowns are not converted into false precision.

7

Assign and compare bands

Assign fictional inherent and residual bands, explain differences, and compare scenarios using the same criteria.

Required output

Threat-risk register with rationale and disagreement log.

Quality check

Every band can be traced to scenario, evidence, controls, uncertainty, and owner input.

8

Choose priority and next action

Set fictional priority, urgency, owner, treatment path, evidence action, review date, and trigger.

Required output

Prioritized risk plan and leadership summary.

Quality check

Priority considers mission timing, dependency, change, and uncertainty—not only the final band.

Scenario Decision Lab

Two Reviewers Produce Different Risk Ratings

The fictional privacy owner rates the supplier free-text field High because sensitive information could be included. The supplier owner rates it Moderate because current population and retention are unknown.

Scenario Decision Lab

A Future-State Scenario Is Scored as Current Risk

The fictional analytics process is still proposed. Fields, purpose, audience, retention, controls, and ownership are not approved, but a reviewer assigns a current residual risk score.

Advanced Challenge

Prioritize Five Fictional Risks under Limited Capacity

The fictional Northbridge team can begin only two major improvements this quarter. Compare supplier-result integrity, archival-identity ownership, notification-change evidence, recovery sequencing, and the future analytics proposal. Choose two actions without relying only on the final risk band.

Compare mission timing

Identify which decisions, changes, expirations, exercises, or service deadlines create urgency.

Compare evidence readiness

Separate scenarios ready for mitigation from scenarios that first require owner or evidence work.

Compare dependency concentration

Identify which scenario affects multiple services, recovery steps, identities, or user workflows.

Compare control opportunity

Estimate which action can produce meaningful reduction with available authority and resources.

Protect future design

Consider whether a pre-implementation decision can prevent expensive or persistent risk.

Document deferred risk

Assign owners, monitoring, evidence actions, review dates, and escalation triggers for scenarios not selected.

Challenge output

Produce a fictional prioritization memo with criteria, two chosen actions, three deferred actions, evidence needs, expected risk reduction, owner capacity, recovery effect, uncertainty, monitoring, escalation triggers, and a leadership explanation of why priority is broader than a single score.

Defender Habits

Risk Ranking in Threat Models Checklist

Check Your Understanding

A3.6 Mini Quiz: Risk Ranking in Threat Models

Choose your answers first. Explanations appear only after submission.

1. Which statement best describes risk ranking?

2. Why should impact and likelihood be rated separately?

3. A fictional control appears in a design document but has no operating evidence. How should it be treated?

4. What is the best response to decision-blocking uncertainty?

5. What is residual risk?

6. Why can a Moderate scenario still be urgent?

7. Which portfolio approach is safest?

Portfolio Prompt

Portfolio Prompt

Create a fully fictional Threat-Risk Register for the Northbridge Student-Support Portal. Include purpose, scope, exclusions, safety boundary, ranking method, definitions for impact, likelihood, exposure, control strength, uncertainty, confidence, inherent risk, residual risk, priority, urgency, and review bands; at least fifteen fictional scenarios; affected assets; primary and secondary categories; evidence and evidence limits; impact dimensions; likelihood factors; exposure; control maturity; recovery; uncertainty; confidence; inherent and residual bands; disagreement records; current-state or future-state label; scenario owner; risk owner; treatment decision; evidence actions; mitigation readiness; monitoring; review date; change triggers; leadership summary; technical appendix; reflection; and a statement that every organization, asset, actor, system, scenario, record, control, score, owner, date, decision, and outcome is invented.

Publish the fictional ranking criteria before assigning any bands or numbers.
Use one stable scenario per row and explain impact, likelihood, controls, uncertainty, and confidence separately.
Do not count a control as effective merely because it is listed in a policy, diagram, or tool inventory.
Use provisional or decision-blocked status when evidence is insufficient for a responsible final ranking.
Keep the entire artifact completely fictional, defensive, non-operational, privacy-safe, evidence-aware, and suitable for a public learning portfolio.

Confidence / Readiness Reflection

Are You Ready to Choose Mitigations?

Before moving to A3.7, rate your readiness from 1 to 5 for scenario definition, impact, likelihood, exposure, control evidence, uncertainty, confidence, inherent risk, residual risk, owner disagreement, urgency, prioritization, maintenance, and complete fictionalization.

I can explain why a risk score is a decision aid rather than an objective prediction.
I can separate threat category, impact, likelihood, control strength, uncertainty, priority, urgency, and intent.
I can use defined fictional criteria consistently across different scenario types.
I can distinguish designed controls from operating, monitored, reviewed, and resilient controls.
I can preserve evidence gaps and decision-blocking uncertainty without guessing.
I can explain inherent and residual risk and show how supported controls affect the difference.
I can document disagreement and identify the authorized owner of the final decision.
I can create a complete fictional risk register without copying, modifying, or exposing real organizational information.
Record one fictional ranking that changed after control evidence, one uncertainty that blocked a final decision, one disagreement that improved the rationale, one urgency factor outside the risk band, and one question you will carry into A3.7 mitigation selection.

Key Takeaways

What You Should Remember

1.Risk ranking is a structured fictional decision process—not a prediction, proof, or guarantee.
2.Rank specific scenarios rather than entire systems, suppliers, roles, or categories.
3.Impact, likelihood, exposure, control strength, uncertainty, confidence, priority, urgency, and intent answer different questions.
4.Threat category does not determine severity.
5.A listed control should reduce residual risk only when relevant evidence supports its design, implementation, operation, review, or resilience.
6.Uncertainty should remain visible and can justify evidence work, provisional status, or decision blocking.
7.Inherent risk reflects the fictional scenario before control effects; residual risk reflects what remains after supported controls and limitations.
8.Priority may depend on mission timing, active change, dependency, owner capacity, evidence readiness, and mitigation opportunity—not only the final band.
9.Risk rationales, disagreement, owners, review dates, triggers, and version history make rankings explainable and maintainable.
10.Every CyberShield risk register and artifact must remain fully fictional, authorized, defensive, non-operational, privacy-safe, and incapable of exposing real systems or people.

Navigation

Continue Module A3

Next, use the fictional threat-risk register to choose layered mitigations across design, prevention, detection, response, recovery, privacy, governance, communication, and evidence.