Don't worry, no one is judging, IriusRisk is here to help!
Contents
Technical Countermeasure Report
Threat modeling isn't a one and done activity. As your application, architecture or micro service evolves, so should your threat model. And so it is important that you revisit and review what has been done, to answer the final of Adam Shostack’s Four Questions; Did we do a good job?
Find this option on the top left of your screen, next to the threat model name. Choose the three ellipses and then select 'Reporting'.
There are four default reports to choose from and can be exported in a variety of formats, including PDF, XLS, XLSX, DOCX and CSV. And most recently, HTML has been added to the Technical Countermeasures Report, as of release 4.31 (July 2024). With the other three reports to following during September and October:
Choose the report from the drop down and select the ‘Create report’ button. The only one which differs, is the Compliance Report, as you can choose a Standard such as PCI DSS and export based upon that compliance need.
From version 4.36.0 of IriusRisk, you will find a newly designed Compliance Report and a new HTML format replacing the less standardized DOCX. Open the report from your Downloads Folder. The report will show you an image of your Project diagram, and then will align your Required Countermeasures to chapters within the chosen Standard. See example below:
In version 4.33.0 of IriusRisk, you will find a newly designed Current Risk Summary Reports and a new HTML format replacing the less standardized DOCX. The spreadsheet formats (CSV, XLS, and XLSX) have also been adapted. The HTML format makes copying information and repurposing it much easier.
Content
Report Structure Enhancements
In the following image appears the improved version (right side) versus current version (left side):
In version 4.31.0 of IriusRisk, you will find a newly designed Technical Countermeasure Reports along with a new HTML format replacing the less standardized DOCX because it is less portable and HTML can be easily integrated into various tools, such as email platforms. Additionally, the spreadsheet formats (CSV, XLS, and XLSX) have been adapted to contain more precise information.
Report Structure Enhancements
Here is an example to show the previous report view on the left, and the new improved view on the right.
More Fashion-Forward Detailed Content in the Test Results Breakdown
Appendix Improvements
Total Countermeasures: Clear display of the total countermeasures.
The final report shows you your risk summary and distribution in the form of a chart like the below.
In addition, it provides a Risk Mitigation Summary with risk ratings and the percentage of implemented countermeasures. It then lists the threats per component where all countermeasures are not implemented or the weaknesses test result failed.
Finally, customers can also use their own Business Intelligence (BI) tools to pull the data from IriusRisk, using API endpoints to export into other tools and software.
We don't hold your data to ransom! If you’d like to export all your threat model data, the diagram, threats etc. then you can do so no problem. Under the ellipses, choose ‘Export data model’, name the threat model, and it will then download in an XML format. We have customers that then use this data in other tools such as PowerBI, and ASPM tools like ArmorCode for a single source of truth.
If you navigate to ‘Home’ then you are presented with a dashboard. The top left shows your risk score, which should have reduced based upon implemented countermeasures to mitigate your threats effectively. It also highlights test results, countermeasures states and your threat risk distribution.