Scoring assistant
Scoring a risk scenario is where assessments get subjective: two analysts look at the same situation and pick different numbers. The Scoring assistant replaces the guess with a structured questionnaire based on the OWASP Risk Rating Methodology. You answer a fixed, short set of questions about the attacker, the weakness and the consequences; the assistant computes probability and impact scores and maps them onto the risk matrix you selected, so everyone scoring the same way lands in the same cell.
Where to find it
Section titled “Where to find it”Risk → Scoring assistant in the sidebar. The page needs at least one risk matrix loaded; if none is available, import one from the libraries store first.
How it works
Section titled “How it works”Pick the Risk matrix at the top — the assistant’s output is expressed on that matrix’s scales, so choose the one the scenario you are scoring uses. Then work through four groups of factors. Each answer contributes to a running score shown beside the group.
Threat agent factors
Section titled “Threat agent factors”Who is attacking, and how capable are they?
- Skill level — from no technical skills through to security penetration skills.
- Motive — low or no reward, possible reward, high reward.
- Opportunity — what access and resources the attack demands, from full access or expensive resources required down to none.
- Size — how large the group is, from developers and system administrators up to anonymous internet users.
Vulnerability factors
Section titled “Vulnerability factors”How easy is the weakness to find, use and get away with?
- Ease of discovery — practically impossible, difficult, easy, automated tools available.
- Ease of exploit — theoretical, difficult, easy, automated tools available.
- Awareness — unknown, hidden, obvious, public knowledge.
- Intrusion detection — active detection in the application, logged and reviewed, logged without review, not logged.
Together these two groups produce the Probability side of the score.
Impact: business or technical
Section titled “Impact: business or technical”The impact side has two alternative groups, and you choose which one applies.
Business impact factors is the default: financial damage, reputation damage, non-compliance and privacy violation. Score these when you can reason about consequences to the organization — which is the better analysis when you can do it.
When you cannot, tick Ignore on the business impact panel. That greys it out, activates Technical impact factors instead — loss of confidentiality, integrity, availability and accountability — and switches the impact score to the technical reading. Only one of the two contributes at a time.
Reading the result
Section titled “Reading the result”The result strip shows three things: the Probability level and score, the Impact level and score, and the Risk level between them, coloured with the matrix’s own palette. Above it, the Assessment vector is a compact string of every answer you gave — copy it into the scenario’s Justification field so the score can be reconstructed and challenged later.
Related
Section titled “Related”- Risk scenarios — where the scores belong.
- Risk matrices — the scales the assistant maps onto.
- Risk assessments — the study the scenario sits in.
