Assumptions & Constraints

Assumptions & Constraints (ACs) can be pre-configured in a separate page 'Assumptions & Constraints'. These ACs are useful to assure consistent risk assessment.

Assumption & Constraint image

It is possible to define categories that can be assigned to assumptions. This can be useful for further tracking. For example, there could be categories for assumptions to the environment or implementation, or for assessment definitions.

ACs enable the creation of definitions (No. 1), which are used for automating risk assessment. Multiple definitions can be added that set the configured value, if linked to an attack scenario.

The pre-configured ACs are added to a new project on creation. Linking the project-ACs can be done via the chain button shown in Attack Scenario view (No. 5).