Skip to content

Scoring assistant

Scoring a risk scenario is where assessments get subjective: two analysts look at the same situation and pick different numbers. The Scoring assistant replaces the guess with a structured questionnaire based on the OWASP Risk Rating Methodology. You answer a fixed, short set of questions about the attacker, the weakness and the consequences; the assistant computes probability and impact scores and maps them onto the risk matrix you selected, so everyone scoring the same way lands in the same cell.

Risk → Scoring assistant in the sidebar. The page needs at least one risk matrix loaded; if none is available, import one from the libraries store first.

Pick the Risk matrix at the top — the assistant’s output is expressed on that matrix’s scales, so choose the one the scenario you are scoring uses. Then work through four groups of factors. Each answer contributes to a running score shown beside the group.

Who is attacking, and how capable are they?

  • Skill level — from no technical skills through to security penetration skills.
  • Motive — low or no reward, possible reward, high reward.
  • Opportunity — what access and resources the attack demands, from full access or expensive resources required down to none.
  • Size — how large the group is, from developers and system administrators up to anonymous internet users.

How easy is the weakness to find, use and get away with?

  • Ease of discovery — practically impossible, difficult, easy, automated tools available.
  • Ease of exploit — theoretical, difficult, easy, automated tools available.
  • Awareness — unknown, hidden, obvious, public knowledge.
  • Intrusion detection — active detection in the application, logged and reviewed, logged without review, not logged.

Together these two groups produce the Probability side of the score.

The impact side has two alternative groups, and you choose which one applies.

Business impact factors is the default: financial damage, reputation damage, non-compliance and privacy violation. Score these when you can reason about consequences to the organization — which is the better analysis when you can do it.

When you cannot, tick Ignore on the business impact panel. That greys it out, activates Technical impact factors instead — loss of confidentiality, integrity, availability and accountability — and switches the impact score to the technical reading. Only one of the two contributes at a time.

The result strip shows three things: the Probability level and score, the Impact level and score, and the Risk level between them, coloured with the matrix’s own palette. Above it, the Assessment vector is a compact string of every answer you gave — copy it into the scenario’s Justification field so the score can be reconstructed and challenged later.