R — Refine the scenario
Confirm one fictional scenario, affected assets, actor context, state, category, scope, evidence, and owners.
Learn how professional defenders compare fictional threat scenarios using defined impact, likelihood, exposure, control strength, uncertainty, confidence, mission context, dependency, and recovery criteria. Build priorities that are explainable and revisable without pretending that a score is an objective prediction.
Lesson Progress
High School Advanced • A3: Threat Modeling • Lesson 6 of 10
Readiness Check
0/6 ready
Professional Hook
A fictional Northbridge reviewer assigns the supplier-result scenario a score of 19. The number appears exact, but the worksheet does not define its scale, show how delay and stale state affect mission impact, explain whether queue controls operate, record uncertainty about source health, or identify the risk owner. Another reviewer gives the same scenario a score of 8. Neither number is useful until the team agrees on criteria and documents evidence.
Weak ranking
“Risk score: 19, Critical.” No scenario definition, scale, evidence, controls, uncertainty, owner, disagreement, recovery, or review trigger is shown.
Strong ranking
“Residual risk: High, with moderate confidence. Impact is High because stale case state can affect decisions and users; likelihood is Moderate based on one exercise and incomplete current-state evidence; control effectiveness is only partially demonstrated.”
Exactly Five Learning Objectives
Objective 1
Explain fictional risk ranking as a structured decision process that compares evidence, impact, likelihood, exposure, control strength, uncertainty, mission context, and recovery—not as an objective prediction.
Objective 2
Define consistent fictional ranking scales and criteria for impact, likelihood, exposure, control effectiveness, confidence, uncertainty, and residual risk.
Objective 3
Evaluate fictional threat scenarios without confusing threat category, possibility, severity, actor intent, exploitability, or missing evidence.
Objective 4
Document fictional ranking rationale, evidence, assumptions, unknowns, disagreements, owners, review triggers, and confidence so that priorities remain explainable and revisable.
Objective 5
Create a portfolio-ready fictional threat-risk register that remains ethical, defensive, non-operational, privacy-safe, evidence-aware, and completely invented.
Why This Matters
Fictional teams cannot improve every concern at the same time. Risk ranking helps them compare scenarios, decide where evidence is missing, identify the most important mitigations, schedule reviews, prepare recovery, communicate uncertainty, and assign accountable owners. Poor ranking can waste effort, hide human impact, or create false confidence.
What fictional mission, user, data, identity, privacy, service, evidence, recovery, safety, or trust harm could result?
How plausible is the fictional scenario under current preconditions, exposure, actor opportunity, controls, change, history, and recovery?
Which owner should gather evidence, reduce risk, monitor, accept residual exposure, escalate, or review the scenario?
Core Framework
Confirm one fictional scenario, affected assets, actor context, state, category, scope, evidence, and owners.
Review mission, data, privacy, identity, availability, safety, evidence, recovery, user, and trust consequences.
Evaluate preconditions, opportunity, reachability, frequency, change, complexity, detectability, and dependencies.
Distinguish controls that are proposed, designed, implemented, operating, monitored, reviewed, and resilient.
Record assumptions, unknowns, stale evidence, conflict, confidence, and decision-blocking gaps.
Assign inherent and residual bands, priority, urgency, treatment, owners, review dates, and triggers.
Decision-ready risk statement
This fictional scenario has a documented inherent and residual risk band based on defined impact, likelihood, exposure, control, uncertainty, mission, and recovery criteria. The ranking cites evidence and limits, records owner disagreement, states confidence, explains the next action, and identifies review triggers. It does not claim that harm will occur.
Advanced Vocabulary
A structured fictional comparison of threat scenarios using defined criteria so owners can decide what requires attention first.
The fictional degree of harm to mission, people, data, identity, privacy, service, evidence, safety, recovery, trust, or organizational responsibility if a scenario occurs.
A reasoned fictional estimate of how plausible a scenario is under current assumptions, exposure, actor opportunity, control state, history, and evidence.
The fictional degree to which an asset, actor relationship, entry point, flow, boundary, dependency, or capability is reachable, shared, privileged, externally dependent, or difficult to observe.
The fictional degree to which safeguards are appropriately designed, implemented, operating, monitored, reviewed, and able to fail safely.
The fictional extent to which prevention, detection, response, recovery, privacy, governance, communication, and source-health controls address a scenario.
The fictional degree to which missing evidence, stale records, assumptions, conflicting sources, unknown ownership, or incomplete scope limits confidence.
A documented fictional judgment about how strongly the available evidence supports the ranking.
A fictional view of risk before considering the expected effect of current controls.
A fictional view of the risk that remains after considering current controls, limitations, dependencies, uncertainty, and recovery.
The fictional role authorized to decide whether residual risk is accepted, reduced, transferred, avoided, monitored, or escalated.
The fictional role responsible for validating the threat scenario, maintaining evidence, coordinating mitigations, and reviewing changes.
A defined fictional factor used consistently across scenarios, such as impact, likelihood, exposure, control strength, uncertainty, recovery, or mission dependence.
A fictional ordered set of labels such as Low, Moderate, High, and Very High where the order matters more than exact numerical distance.
Presenting fictional scores or percentages as more exact, objective, or predictive than the evidence supports.
A fictional comparison tool that combines defined impact and likelihood bands while preserving evidence, uncertainty, and context.
A fictional organization's general willingness to accept different kinds and levels of risk while pursuing its mission.
A fictional boundary around how much variation, delay, exposure, uncertainty, or residual harm is acceptable for a specific objective.
The fictional order in which scenarios should receive owner attention, evidence collection, mitigation, monitoring, or review.
The fictional time sensitivity of a decision based on exposure, active change, control gap, dependency, deadline, or possible impact.
The fictional speed at which harm could develop after a scenario begins.
The fictional ability to restore correct technical and business state, authority, evidence, communication, and trust within acceptable time.
The fictional explanation that connects scenario, criteria, evidence, assumptions, controls, uncertainty, owners, and the resulting priority.
A fictional change or event that requires the ranking to be reconsidered, such as a new supplier, control change, incident lesson, evidence gap, ownership change, or recovery result.
Instructional Section 1
Evaluate a specific fictional actor–action–asset–condition–outcome scenario rather than assigning one score to an entire system, role, supplier, or category.
Strong practice
Rank “delayed supplier results update stale case state when reconciliation is incomplete,” not “supplier risk.”
If ignored
Vague objects hide different impacts, controls, owners, evidence, and recovery needs.
Publish fictional criteria and examples for every impact, likelihood, exposure, control, uncertainty, and confidence band.
Strong practice
Reviewers use the same definitions and record why a scenario fits a band.
If ignored
Teams may use the same label to mean very different things.
Connect each fictional rating to supplied records, owner decisions, diagrams, exercises, events, tickets, reviews, and source-health information.
Strong practice
State what evidence supports, what it does not prove, and when it was reviewed.
If ignored
Plausibility, familiarity, fear, or confidence can replace evidence.
Identity, privacy, integrity, availability, governance, or resilience labels describe concern type—not importance.
Strong practice
Apply the same risk criteria across all relevant category families.
If ignored
Teams may automatically over-rank some categories and under-rank others.
A highly harmful fictional outcome may be unlikely, while a frequent condition may have limited impact.
Strong practice
Score and explain both dimensions independently before combining them.
If ignored
One dramatic consequence can dominate the entire ranking.
Consider whether fictional controls are designed, implemented, operating, monitored, reviewed, and resilient.
Strong practice
Record control evidence and limitations rather than assuming a listed control works.
If ignored
A control inventory can create false confidence.
Missing ownership, incomplete fields, stale reviews, conflicting sources, or unhealthy evidence should affect confidence and follow-up.
Strong practice
Record uncertainty separately and assign an evidence owner.
If ignored
Unknowns are silently converted into low or high risk without explanation.
Evaluate fictional user, service, privacy, safety, fairness, communication, recovery, and trust outcomes—not only technical effects.
Strong practice
Use mission owners and affected-user perspectives in impact review.
If ignored
Technical availability may be treated as success while business or human state remains unsafe.
Preserve fictional differences between security, privacy, operations, data, supplier, recovery, support, and mission owners.
Strong practice
Record each rationale, evidence, uncertainty, and final decision owner.
If ignored
A forced consensus can hide meaningful assumptions and tradeoffs.
Update fictional priorities when assets, actors, interfaces, flows, suppliers, controls, automation, evidence, recovery, or ownership changes.
Strong practice
Use dates, triggers, versions, and named owners.
If ignored
A once-useful score can become a stale source of false confidence.
Instructional Section 2
Fictional impact should be reviewed across multiple dimensions. The strongest dimension may guide the final impact band, but the rationale should preserve all meaningful harms and owner perspectives.
Low
Minor fictional inconvenience with a supported workaround and no meaningful interruption to the service objective.
Moderate
Noticeable delay or reduced quality affecting a limited group or workflow.
High
Major disruption, incorrect decision, or loss of a critical service outcome.
Very High
Severe fictional failure of an essential mission, widespread service, or high-consequence decision process.
Supporting fictional evidence
Service objectives, business-impact notes, user journeys, support themes, leadership decisions, and recovery exercises.
Low
Small, easily corrected fictional record issue with strong detection and reconciliation.
Moderate
Limited incorrect, missing, delayed, duplicated, or stale data requiring owner review.
High
Significant fictional workflow, decision, evidence, or record integrity impact across multiple users or services.
Very High
Widespread or difficult-to-recover fictional corruption of critical data, decisions, evidence, or business state.
Supporting fictional evidence
Validation results, reconciliation, event order, change history, duplicate handling, source health, and data-owner review.
Low
Minimal fictional exposure of low-sensitivity information to a narrowly limited audience with rapid correction.
Moderate
Limited disclosure, over-collection, inappropriate purpose, or retention involving sensitive context.
High
Substantial fictional exposure, misuse, inference, audience expansion, or retention affecting important personal or organizational data.
Very High
Widespread, highly sensitive, or difficult-to-remediate fictional privacy or confidentiality harm.
Supporting fictional evidence
Data classification, field inventory, approved purpose, audience, sharing records, access, retention, deletion, and privacy review.
Low
Narrow fictional authority issue with limited action scope and strong review.
Moderate
Role, assignment, object, approval, or lifecycle weakness affecting a limited set of actions.
High
Broad or privileged fictional authority that can affect sensitive assets, users, configuration, workflow, or recovery.
Very High
Concentrated fictional authority across critical identity, data, service, evidence, and recovery assets with weak separation or review.
Supporting fictional evidence
Role maps, object checks, approvals, access reviews, administrative events, lifecycle, and emergency-access records.
Low
Brief fictional delay with limited user effect and a tested alternate path.
Moderate
Service degradation or dependency failure affecting a defined workflow or group.
High
Sustained fictional outage, hidden backlog, significant delay, or shared dependency failure affecting major services.
Very High
Widespread fictional inability to provide essential service or recover within mission needs.
Supporting fictional evidence
Health, queues, capacity, service objectives, dependency maps, supplier records, support impact, and recovery exercises.
Low
Minor fictional confusion or inconvenience with clear correction and no significant decision consequence.
Moderate
Meaningful delay, confusion, accessibility barrier, or decision-quality effect for some users.
High
Serious fictional harm to service access, fairness, trusted decisions, communication, or vulnerable users.
Very High
Severe fictional harm to people, essential support, safety, rights, or high-consequence decisions.
Supporting fictional evidence
User journeys, support records, complaints, communications, decision reviews, accessibility review, and mission-owner input.
Low
Limited fictional evidence gap with alternative reliable records and low decision impact.
Moderate
Missing context or source-health uncertainty that slows review or weakens confidence.
High
Major fictional inability to attribute actions, validate state, investigate, recover, or support required decisions.
Very High
Widespread fictional loss of trustworthy evidence across critical identity, workflow, recovery, or governance decisions.
Supporting fictional evidence
Event schemas, source health, correlation, tickets, approvals, timestamps, retention, access, and review quality.
Low
Fictional state can be restored quickly with tested evidence and little user impact.
Moderate
Recovery requires manual work, additional validation, or limited communication repair.
High
Recovery is slow, dependent, uncertain, or likely to leave stale, duplicated, or incorrect business state.
Very High
Fictional recovery cannot reliably restore critical service, authority, data, evidence, communication, or trust.
Supporting fictional evidence
Restore tests, dependency order, recovery identity, configuration baselines, reconciliation, communications, closure, and lessons learned.
Instructional Section 3
Lower likelihood or exposure
Many independent fictional conditions must align and current evidence shows strong barriers.
Higher likelihood or exposure
Few conditions are required, or one common workflow state may be enough.
Evidence
Abuse-case preconditions, control design, role scope, workflow state, supplier dependency, and review results.
Lower likelihood or exposure
Narrow fictional role, uncommon workflow, limited object set, short time window, and strong approval.
Higher likelihood or exposure
Broad role, frequent workflow, shared interface, long-lived access, or common service identity.
Evidence
Actor inventory, role map, assignment, frequency, lifecycle, interface use, and approval records.
Lower likelihood or exposure
Limited fictional reachability, constrained interface, isolated environment, restricted audience, and strong ownership.
Higher likelihood or exposure
Public, shared, supplier-dependent, privileged, broadly reachable, or difficult-to-observe relationship.
Evidence
Entry-point inventory, trust boundaries, network zones, supplier relationships, user population, and interface ownership.
Lower likelihood or exposure
Fictional controls are specifically designed, operating, monitored, tested, reviewed, and fail safely.
Higher likelihood or exposure
Controls are missing, generic, untested, stale, inconsistently applied, or unsupported by evidence.
Evidence
Control requirements, test results, monitoring, reviews, exceptions, source health, and failure exercises.
Lower likelihood or exposure
No similar fictional events in a relevant period, with healthy evidence and strong control review.
Higher likelihood or exposure
Repeated fictional tickets, exercises, failures, or near misses show similar conditions.
Evidence
Tickets, incident summaries, exercises, alert reviews, support patterns, and change history.
Lower likelihood or exposure
Stable fictional design, limited dependencies, clear ownership, controlled release, and current documentation.
Higher likelihood or exposure
Recent change, multiple suppliers, complex state, many handoffs, temporary interfaces, or unclear ownership.
Evidence
Change requests, architecture versions, dependency maps, owner records, release evidence, and temporary-access records.
Lower likelihood or exposure
Fictional evidence reliably identifies unsafe state early enough for intervention.
Higher likelihood or exposure
Evidence is delayed, ambiguous, unhealthy, incomplete, or available only after business impact.
Evidence
Event meaning, source health, alert thresholds, correlation, dashboard review, and response timing.
Lower likelihood or exposure
Fictional restoration and reconciliation are tested, timely, and supported by trusted evidence.
Higher likelihood or exposure
Recovery depends on stale identities, uncertain state, manual repair, supplier coordination, or incomplete reconciliation.
Evidence
Recovery tests, dependency order, identity records, reconciliation, communication, and closure review.
Instructional Section 4
A fictional policy, tool, diagram, or requirement should not reduce residual risk merely because it exists on paper. Review control evidence in stages.
The fictional control may be proposed, assumed, undocumented, unowned, or unsupported by evidence.
Fictional evidence
No current design decision, implementation evidence, operating result, monitoring, test, or owner confirmation.
Ranking effect
Do not count the control as reducing residual risk. Increase uncertainty and assign an evidence owner.
The fictional control has a documented purpose, owner, scope, and expected behavior.
Fictional evidence
Design record, policy, architecture decision, role definition, workflow, or requirement.
Ranking effect
Recognize design intent but do not assume implementation or operating effectiveness.
The fictional control is represented in configuration, workflow, process, or deployed design evidence.
Fictional evidence
Approved configuration summary, workflow record, deployment evidence, role mapping, or interface decision.
Ranking effect
Consider partial risk reduction while preserving uncertainty about actual operation.
The fictional control produces expected outcomes and evidence under normal and relevant failure conditions.
Fictional evidence
Event output, test result, review sample, source health, ticket analysis, or exercise outcome.
Ranking effect
Consider stronger reduction when evidence is current, relevant, and complete.
The fictional control has health, ownership, exception, performance, failure, and review evidence.
Fictional evidence
Metrics, source-health dashboard, access review, control test, exception log, and owner sign-off.
Ranking effect
Use the strongest justified reduction while documenting limitations, dependencies, and residual risk.
The fictional control continues or fails safely during disruption and supports recovery and reconciliation.
Fictional evidence
Failure test, alternate path, recovery exercise, integrity validation, communication, and closure review.
Ranking effect
Account for reduced impact or likelihood only where recovery evidence supports the claim.
Instructional Section 5
Fictional scope, owners, evidence, control state, affected assets, and scenario conditions are current and consistent.
Recommended action
Proceed with ranking while retaining normal review triggers.
Some fictional assumptions, evidence sources, owner decisions, or control details remain incomplete but the central scenario is understandable.
Recommended action
Rank with caution, document confidence, and assign targeted evidence actions.
Important fictional ownership, exposure, data, identity, control, event, source-health, or recovery information is missing or conflicting.
Recommended action
Avoid false precision, consider a provisional priority, and escalate evidence collection.
The fictional scenario, affected assets, current state, control state, or business context is too unclear for a responsible ranking.
Recommended action
Pause final ranking, preserve the concern, assign owners, and define the evidence needed to continue.
Instructional Section 6
The fictional scenario has limited impact and likelihood, strong controls, high recoverability, and low uncertainty.
Typical response
Maintain controls, document rationale, monitor changes, and review on schedule.
Important warning
Low does not mean impossible or irrelevant; it means lower priority under current evidence and criteria.
The fictional scenario has meaningful but bounded impact or likelihood, partial control coverage, manageable recovery, or moderate uncertainty.
Typical response
Assign an owner, plan proportionate improvement, collect missing evidence, and monitor review triggers.
Important warning
Moderate scenarios can become urgent when context, exposure, control state, or dependencies change.
The fictional scenario can significantly affect mission, people, privacy, integrity, service, evidence, authority, or recovery and has credible conditions or weak control coverage.
Typical response
Prioritize owner review, evidence validation, mitigation planning, monitoring, recovery preparation, and leadership visibility.
Important warning
High is not proof that harm will occur; it is a decision priority supported by defined criteria.
The fictional scenario combines severe impact, credible conditions, broad exposure, weak controls, difficult recovery, concentrated dependency, or major uncertainty requiring immediate owner attention.
Typical response
Escalate to authorized leadership and owners, define near-term protective action, preserve evidence, and review residual risk frequently.
Important warning
Very High should be rare, evidence-aware, and justified—not used as a dramatic label.
Professional Workflow
Use one fictional abuse case with defined actor context, assets, preconditions, capability, outcome, evidence, controls, owners, and state.
Required output
Stable scenario identifier and decision statement.
Quality check
The scenario is specific enough that different reviewers are ranking the same thing.
Confirm current or future state, affected environment, trust boundary, primary category, meaningful secondary categories, and exclusions.
Required output
Scope and category record.
Quality check
Category labels organize the scenario but do not determine severity.
Review mission, data, privacy, identity, availability, safety, evidence, recovery, and trust impacts.
Required output
Impact table with rationale, evidence, owner input, and strongest dimension.
Quality check
Impact is bounded and does not rely on catastrophic language.
Review preconditions, opportunity, exposure, control reliability, history, change, detectability, and recovery difficulty.
Required output
Likelihood table with evidence and assumptions.
Quality check
Likelihood is not inferred from impact or category.
Determine whether each fictional control is merely proposed, designed, implemented, operating, monitored, reviewed, and resilient.
Required output
Control-evidence matrix with limitations and owners.
Quality check
A listed control is not counted as effective without supporting evidence.
Identify missing ownership, stale records, conflicting evidence, source-health gaps, incomplete scope, or untested recovery.
Required output
Uncertainty level, confidence statement, and evidence action list.
Quality check
Unknowns remain visible rather than being converted into a score.
Use defined fictional criteria to compare risk before and after control evidence.
Required output
Inherent band, residual band, rationale, and disagreement record.
Quality check
The result explains how controls and uncertainty changed the decision.
Consider mission deadlines, active change, exposure, dependencies, review dates, recovery, and owner capacity.
Required output
Priority order, urgency, owner, and next decision date.
Quality check
Priority is not based only on the final band.
Decide whether to reduce, avoid, transfer, accept, monitor, gather evidence, or escalate the fictional risk.
Required output
Risk treatment decision and residual-risk owner.
Quality check
The decision is authorized and tied to specific conditions and evidence.
Set review triggers for changes in assets, identity, flows, suppliers, controls, evidence, incidents, recovery, ownership, or mission.
Required output
Version, review date, triggers, history, and retirement criteria.
Quality check
The ranking can be revised when context changes.
Worked Fictional Examples
Impact
High integrity and service impact because incorrect case status can affect decisions, communication, duplicate action, and trust.
Likelihood
Moderate because a similar delay occurred in a fictional exercise, but final production behavior and current controls remain uncertain.
Control evidence
Schema validation is designed; source-health reporting operates; state reconciliation and duplicate handling are not fully evidenced.
Uncertainty
Moderate to high because queue-health meaning, ordering, reconciliation, and current owner evidence are incomplete.
Inherent risk
High
Residual risk
High
Ranking rationale
Existing evidence does not justify enough reduction. The scenario deserves priority owner review and mitigation planning.
Impact
Moderate to high privacy and confidentiality impact depending on content, population, access, retention, and purpose.
Likelihood
Unclear because the field inventory shows the field exists but does not prove it is populated in current requests.
Control evidence
Data minimization is expected, but owner approval, field validation, supplier retention, and evidence are incomplete.
Uncertainty
High
Inherent risk
High
Residual risk
Provisional Moderate or High pending evidence
Ranking rationale
Final ranking should remain provisional because current use and control state are not sufficiently established.
Impact
Potentially high identity, governance, retention, recovery, and evidence impact because the service may affect archival state.
Likelihood
Moderate based on current active status and lifecycle gap, but misuse or excessive permission is not proven.
Control evidence
Service identity exists and activity may be logged, but ownership, access review, permission scope, and retirement are not confirmed.
Uncertainty
High
Inherent risk
High
Residual risk
High provisional
Ranking rationale
Ownership and authority evidence are needed before a more precise residual ranking.
Impact
Moderate because incorrect preferences can affect privacy, communication, workflow, user trust, and support effort.
Likelihood
Moderate because multiple fictional tickets show the evidence gap, but authorization or harmful outcomes are not proven.
Control evidence
Support role and tickets exist; verification, confirmation, event correlation, and review coverage are incomplete.
Uncertainty
Moderate
Inherent risk
Moderate
Residual risk
Moderate
Ranking rationale
The scenario warrants workflow and evidence improvement but does not justify an extreme rating.
Impact
High resilience, integrity, availability, safety, and trust impact because technical availability can return with incorrect business state.
Likelihood
Moderate because the condition occurred in one fictional exercise and dependencies remain complex.
Control evidence
Recovery plan and backups exist, but ordering, identity validation, reconciliation, communication, and closure evidence are incomplete.
Uncertainty
Moderate
Inherent risk
High
Residual risk
High
Ranking rationale
Recovery evidence supports a meaningful priority even though future frequency is unknown.
Impact
Potentially high privacy, confidentiality, governance, accountability, and interpretation impact.
Likelihood
Not yet applicable as current exposure because the process is proposed future state.
Control evidence
Purpose, fields, audience, retention, access, owner, review, and safeguards are not yet approved.
Uncertainty
Decision-blocking for current-state risk ranking.
Inherent risk
Future-state High potential
Residual risk
Not yet assigned
Ranking rationale
Treat as a design decision and pre-implementation requirement, not as a current incident or deployed risk.
Fictional Risk Matrix
This conceptual matrix is fully invented. It shows how impact and likelihood may support comparison, but it does not replace control, uncertainty, mission, owner, urgency, or recovery analysis.
| Likelihood ↓ / Impact → | Low | Moderate | High | Very High |
|---|---|---|---|---|
| Very High | Moderate | High | Very High | Very High |
| High | Moderate | High | High | Very High |
| Moderate | Low | Moderate | High | High |
| Low | Low | Low | Moderate | High |
Fake Dashboard
Fictional scenario ranking, control evidence, uncertainty, and ownership status for training only.
Scenarios ready for final ranking
11 / 18
Seven scenarios still lack sufficient ownership, control, exposure, current-state, or recovery evidence.
High residual risks
4
Supplier-result integrity, archival identity governance, recovery sequencing, and temporary-interface ownership require prioritized review.
Decision-blocking uncertainty
2
The proposed analytics process and unclear free-text supplier field need owner decisions before final ranking.
Fake SOC Alert
Source: Fake Northbridge Risk Governance Console • Time: 2:14 PM
Fake Log Panel
09:00 METHOD impact-bands='defined' likelihood-bands='defined' 09:08 METHOD controls='designed,implemented,operating,reviewed' 09:16 METHOD uncertainty='low,moderate,high,blocking' 09:24 SCENARIO supplier-result readiness='ready' 09:32 IMPACT supplier-result='high' rationale='stale-case-state' 09:40 LIKELIHOOD supplier-result='moderate' evidence='exercise+gaps' 09:48 CONTROL supplier-result='partial' reconciliation='not-evidenced' 09:56 RESIDUAL supplier-result='high' confidence='moderate' 10:04 SCENARIO supplier-note readiness='provisional' 10:12 UNCERTAINTY supplier-note='high' current-use='unknown' 10:20 SCENARIO analytics readiness='blocked' state='future' 10:28 SCENARIO archive-identity residual='high-provisional' 10:36 SCENARIO notification-change residual='moderate' 10:44 SCENARIO recovery-sequence residual='high' 10:52 QUALITY false-precision='detected' numeric-scores='paused' 11:00 OWNER risk-decisions='assigned' 11:08 REVIEW privacy='complete' operations='complete' 11:16 REVIEW mission='pending' recovery='complete' 11:24 CONFIDENCE register='medium' 14:14 ALERT method='undefined-numeric-score'
Training note: this is fake data for defensive analysis practice only.
Fictional Evidence Matrix
Observation
Processing-result events were delayed for twenty-two minutes while the source-health indicator remained Green.
Supports
Availability, integrity, accountability, dependency, and resilience criteria require review.
Does not prove
The dashboard does not prove data loss, malicious activity, incorrect final state, or future frequency.
Ranking use
Increase evidence attention and uncertainty; do not automatically assign Very High severity.
Observation
Users submitted duplicate records after delayed status notifications.
Supports
User, workflow, service, support, integrity, and communication impact may be meaningful.
Does not prove
The pattern does not prove one cause or that every duplicate produced the same impact.
Ranking use
Use as bounded impact evidence and preserve causal uncertainty.
Observation
The processing request may include a free-text support note.
Supports
Privacy and confidentiality impact could be meaningful if the field is populated, unnecessary, retained, or broadly accessed.
Does not prove
Current population, purpose, access, retention, and approval are not established.
Ranking use
Treat residual ranking as provisional and assign evidence actions.
Observation
An archival service identity is active, lacks a confirmed owner, and is past its review date.
Supports
Exposure, governance, identity, authority, retention, and recovery uncertainty are elevated.
Does not prove
The record does not prove compromise, misuse, broad permission, or harmful activity.
Ranking use
Increase uncertainty and owner urgency without claiming an incident.
Observation
Application service returned before notification and archival dependencies were validated, producing stale messages and repeated tasks.
Supports
High potential impact and credible recovery complexity are supported by exercise evidence.
Does not prove
One exercise does not establish production frequency or prove all current controls are ineffective.
Ranking use
Support a meaningful resilience priority while preserving likelihood uncertainty.
Observation
Several preference changes lack a recorded reason and user confirmation.
Supports
Accountability and workflow evidence are incomplete across multiple records.
Does not prove
The evidence does not prove unauthorized action, incorrect preference, intent, or user harm.
Ranking use
Support a Moderate evidence and process priority rather than a dramatic rating.
Observation
A proposed process may combine several event sources, but purpose, fields, audience, retention, and ownership remain unresolved.
Supports
Potential future privacy, confidentiality, governance, and interpretation impact requires design review.
Does not prove
The proposal is not proof of current collection, use, exposure, or control failure.
Ranking use
Record future-state potential and block final current-state ranking.
Observation
A migration-import channel remains documented as enabled without confirmed current purpose, owner, activity, or retirement.
Supports
Exposure, ownership, lifecycle, identity, evidence, and dependency uncertainty are meaningful.
Does not prove
The inventory does not prove reachability, use, unsafe configuration, or malicious activity.
Ranking use
Assign a governance and evidence priority while avoiding unsupported severity.
Analyze the Evidence
Common Mistakes
Why it fails
A privacy, identity, supplier, or availability label does not determine importance.
Strong correction
Apply the same fictional impact, likelihood, exposure, control, uncertainty, mission, and recovery criteria across scenarios.
Why it fails
A mathematical-looking score can hide subjective definitions and false precision.
Strong correction
Publish criteria, show rationale, preserve evidence, and use numbers only as a support—not a substitute—for judgment.
Why it fails
A severe outcome may be rare, while a common condition may be low impact.
Strong correction
Rate impact and likelihood independently before combining them.
Why it fails
Unknown control state, ownership, exposure, or event history does not prove low risk.
Strong correction
Record uncertainty separately and assign an evidence action.
Why it fails
Uncertainty can justify urgency and caution, but it does not prove severe impact or likely occurrence.
Strong correction
Use provisional ratings, confidence statements, and decision-blocking labels when needed.
Why it fails
A policy, tool, dashboard, or design record may not prove implementation, operation, review, or resilience.
Strong correction
Assess control design, implementation, operation, monitoring, review, failure, and recovery evidence.
Why it fails
One overall score hides different assets, scenarios, owners, controls, evidence, and priorities.
Strong correction
Rank specific fictional scenarios and aggregate only for communication with clear limits.
Why it fails
Technical measures may overlook service access, fairness, communication, privacy, trust, or decision consequences.
Strong correction
Include mission and affected-user perspectives in impact review.
Why it fails
Different fictional owners may reasonably interpret evidence and impact differently.
Strong correction
Record viewpoints, assumptions, evidence, uncertainty, and the authorized final decision.
Why it fails
Real scenarios, controls, owners, suppliers, systems, incidents, recovery details, and priorities can be sensitive.
Strong correction
Invent every organization, asset, actor, scenario, score, record, control, owner, date, decision, and outcome.
Safe Fictional Practice Lab
Define fictional impact, likelihood, exposure, control strength, uncertainty, confidence, inherent risk, residual risk, and review bands before rating scenarios.
Required output
A ranking guide with clear criteria and examples.
Quality check
Two reviewers can explain the same bands even if they reach different evidence-based judgments.
Choose fictional abuse cases with stable scope, assets, owners, evidence, controls, category, and current or future-state labels.
Required output
A risk-ranking queue with readiness status.
Quality check
Decision-blocking cases remain visible but are not forced into final ratings.
Review mission, data, privacy, identity, availability, safety, evidence, recovery, and trust dimensions.
Required output
Impact rationale with owner perspectives and strongest dimensions.
Quality check
The impact statement is bounded, fictional, and supported by evidence.
Review preconditions, actor opportunity, reachability, frequency, change, complexity, history, detectability, and recovery difficulty.
Required output
Likelihood and exposure rationale with assumptions.
Quality check
Likelihood is not copied from impact or category.
Record whether each fictional control is designed, implemented, operating, monitored, reviewed, and resilient.
Required output
Control-evidence table with limitations and owners.
Quality check
Only supported control effects reduce residual risk.
Identify missing, stale, conflicting, unhealthy, proposed, or unowned evidence.
Required output
Uncertainty level, confidence statement, and evidence plan.
Quality check
Unknowns are not converted into false precision.
Assign fictional inherent and residual bands, explain differences, and compare scenarios using the same criteria.
Required output
Threat-risk register with rationale and disagreement log.
Quality check
Every band can be traced to scenario, evidence, controls, uncertainty, and owner input.
Set fictional priority, urgency, owner, treatment path, evidence action, review date, and trigger.
Required output
Prioritized risk plan and leadership summary.
Quality check
Priority considers mission timing, dependency, change, and uncertainty—not only the final band.
Scenario Decision Lab
The fictional privacy owner rates the supplier free-text field High because sensitive information could be included. The supplier owner rates it Moderate because current population and retention are unknown.
Scenario Decision Lab
The fictional analytics process is still proposed. Fields, purpose, audience, retention, controls, and ownership are not approved, but a reviewer assigns a current residual risk score.
Advanced Challenge
The fictional Northbridge team can begin only two major improvements this quarter. Compare supplier-result integrity, archival-identity ownership, notification-change evidence, recovery sequencing, and the future analytics proposal. Choose two actions without relying only on the final risk band.
Compare mission timing
Identify which decisions, changes, expirations, exercises, or service deadlines create urgency.
Compare evidence readiness
Separate scenarios ready for mitigation from scenarios that first require owner or evidence work.
Compare dependency concentration
Identify which scenario affects multiple services, recovery steps, identities, or user workflows.
Compare control opportunity
Estimate which action can produce meaningful reduction with available authority and resources.
Protect future design
Consider whether a pre-implementation decision can prevent expensive or persistent risk.
Document deferred risk
Assign owners, monitoring, evidence actions, review dates, and escalation triggers for scenarios not selected.
Challenge output
Produce a fictional prioritization memo with criteria, two chosen actions, three deferred actions, evidence needs, expected risk reduction, owner capacity, recovery effect, uncertainty, monitoring, escalation triggers, and a leadership explanation of why priority is broader than a single score.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional Threat-Risk Register for the Northbridge Student-Support Portal. Include purpose, scope, exclusions, safety boundary, ranking method, definitions for impact, likelihood, exposure, control strength, uncertainty, confidence, inherent risk, residual risk, priority, urgency, and review bands; at least fifteen fictional scenarios; affected assets; primary and secondary categories; evidence and evidence limits; impact dimensions; likelihood factors; exposure; control maturity; recovery; uncertainty; confidence; inherent and residual bands; disagreement records; current-state or future-state label; scenario owner; risk owner; treatment decision; evidence actions; mitigation readiness; monitoring; review date; change triggers; leadership summary; technical appendix; reflection; and a statement that every organization, asset, actor, system, scenario, record, control, score, owner, date, decision, and outcome is invented.
Confidence / Readiness Reflection
Before moving to A3.7, rate your readiness from 1 to 5 for scenario definition, impact, likelihood, exposure, control evidence, uncertainty, confidence, inherent risk, residual risk, owner disagreement, urgency, prioritization, maintenance, and complete fictionalization.
Key Takeaways
Navigation
Next, use the fictional threat-risk register to choose layered mitigations across design, prevention, detection, response, recovery, privacy, governance, communication, and evidence.