Threat Analysis and Risk Assessment

Articles, guides, and products tagged "Threat Analysis and Risk Assessment" — a combined view of every catalogue resource on this topic.

User guide

E-scooter risk management engineering as the 32nd engineering axis: risk-anticipation meta-axis — ISO 31000:2018 + ISO/IEC 31010:2019 + ISO Guide 73:2009 + Bowtie + ALARP + SFAIRP + LOPA + HAZOP IEC 61882 + FTA IEC 61025 + ETA IEC 62502 + FMEA IEC 60812 + ISO 14971:2019 + ERM COSO 2017 + Kaplan & Garrick 1981 triplet

Engineering deep-dive into risk-management engineering as the 32nd engineering axis and the 15th cross-cutting infrastructure axis — describes the systematic methodology for identification + analysis + evaluation + treatment + monitoring of risks layered over all the other axes: ISO 31000:2018 *Risk management — Guidelines* (8 principles + framework with 6 components + risk-management process with 7 stages), ISO Guide 73:2009 *Risk management — Vocabulary* (61 terms with risk / hazard / consequence / likelihood definitions), ISO/IEC 31010:2019 *Risk assessment techniques* with 41 assessment techniques, Kaplan & Garrick 1981 triplet definition «What scenario? How likely? What consequences?», ALARP (As Low As Reasonably Practicable) + SFAIRP (So Far As Is Reasonably Practicable) UK HSE principles + reverse burden of proof, risk appetite vs risk tolerance ISO 31000 vocabulary distinction, IEC 31010 risk matrix + heat map + risk register tools, HAZOP IEC 61882:2016 deviation/guide-word inductive process-hazard methodology, FMEA IEC 60812:2018 inductive component-level failure-mode analysis, FTA IEC 61025:2006 deductive top-down boolean-logic event-tree, ETA IEC 62502:2010 inductive consequence-tree with branching on mitigation success/failure, Bowtie methodology (CGE Risk Management Solutions formalized 1990s) — combines threats + barriers (preventive + recovery) + consequences around a central top event, LOPA (Layer of Protection Analysis) CCPS 2001 semi-quantitative methodology with IPL (Independent Protection Layer) credit, ISO 14971:2019 *Application of risk management to medical devices* (cross-industry inspiration), ERM (Enterprise Risk Management) COSO 2017 framework with 5 components + 20 principles, 3 Lines of Defense model IIA Position Paper 2013 (updated 2020), risk-based thinking ISO 9001:2015 clause 6.1 + IATF 16949 cross-link, ISO 26262 HARA + ISO 21434 TARA cybersecurity cross-link, ISO 31000:2009 → 2018 simplification (from 11 principles to 8). 31-row cross-axis matrix maps the risk-management concept to each of the 31 prior engineering axes (battery thermal runaway = LOPA with multiple IPLs; brake failure = FTA top event; tire blowout = Bowtie threats+barriers+consequences; ...); 8-step DIY owner risk-management 'tells' checklist (recall registry tracking + safety-related characteristic markings + manufacturer field-issue subscription + warranty RCA depth + accident statistics transparency).

15 min read

User guide

Software and firmware engineering for embedded ECUs of an electric scooter as the 29th engineering axis: UN R156 SUMS + ISO/SAE 21434 + Automotive SPICE 4.0 + MISRA C:2023 + ISO 26262-6:2018 + AUTOSAR Classic R23-11 + ISO/IEC/IEEE 12207:2017 + ISO/IEC/IEEE 29148:2018 + ISO/IEC 25010:2023 + CISA SBOM Minimum Elements + CWE/CVE + CVSS v4.0

Engineering deep-dive into software & firmware engineering as the 29th engineering axis and the twelfth cross-cutting infrastructure axis — describes how firmware of e-scooter embedded ECUs (motor controller + BMS + dashboard + IoT gateway + charger MCU) is developed under MISRA C:2023, validated through the Automotive SPICE 4.0 V-model + SWE.1–SWE.6 + SYS.1–SYS.5 + HWE.1–HWE.4 + MLE.1–MLE.4, OTA-updated under UN R156 SUMS (L-category mandate: Dec 2027 new types / June 2029 existing types), traced through the ISO/IEC/IEEE 12207:2017 software lifecycle's 30 processes in 4 groups (Agreement + Organizational Project-Enabling + Technical Management + Technical), documented via SBOM per CISA Minimum Elements 2025 (Supplier + Component + Version + Unique-IDs + Dependencies + Author + Timestamp + Hash + License + Tool + Generation-Context) in SPDX 2.3 and CycloneDX 1.6 formats, versioned through the ISO/IEC 25010:2023 product quality model's 8 characteristics, qualified at the toolchain level per ISO 26262-8 Clause 11 (TCL1/TCL2/TCL3 + TD1/TD2/TD3), and monitored through CWE Top 25 + CVSS v4.0 (Base + Threat + Environmental + Supplemental). 18 numbered sections.

15 min read