risk assessment

The practice of identifying, characterizing, and prioritizing safety, security, ethical, and deployment vulnerabilities and their likely consequences, and specifying concrete mitigation and policy controls to reduce harm in deployed systems. It includes threat/vulnerability analysis, impact modeling (e.g., multilingual biases or delusional framing), and designing deployment practices that detect and override risky behaviors.

riskassessment

12-Month Skill Trend

Momentum and market value over time
Trending
Score
+20 in 12 mo
96
12 mo agoNow
Career
Value
+$12K in 12 mo
$42K/year
12 mo agoNow

Recommended Survey Paper

Quick overview of the field
View more

Current AI risk mitigation frameworks suffer from fragmentation, terminological ambiguity, and coverage gaps, hindering coordinated multistakeholder governance. To address this, we introduce the first cross-framework taxonomy for AI risk mitigation, systematically synthesizing 831 mitigation measures from 13 prominent frameworks published between 2023 and 2025. Our methodology combines rapid evidence scanning, iterative clustering-based coding, and structured knowledge modeling to develop a four-dimensional classification—governance & oversight, technical safety, operational processes, and transparency & accountability—with 23 granular subcategories. We explicitly resolve semantic inconsistencies in key terms (e.g., “red-teaming,” “risk management”) and deliver a scalable, role-aligned taxonomy alongside a dynamic, open-source database. The resulting resource enables comparative framework analysis and gap identification, supporting national policymaking and AI safety organizations worldwide. All artifacts are publicly released to advance global AI governance infrastructure.

Addressing inconsistent terminology and coverage gaps in AI risk managementOrganizing fragmented AI risk mitigation frameworks into a unified taxonomyProviding a common reference for AI risk mitigation across organizations and governments

Must-Read Papers

Most classic and influential ideas
View more

The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure

Oct 30, 2025
LD
Liming Dong
🏛️ Data61 | CSIRO | Google

Frequent and increasingly sophisticated software supply chain attacks pose systemic security threats to critical infrastructure, while existing security frameworks suffer from fragmented lifecycles, misalignment with regulatory requirements, and significant coverage gaps. Method: This study integrates ISO/IEC 27001, NIST SSDF, and Australian critical infrastructure security regulations to propose a multidimensional analytical framework grounded in the “4W+1H” paradigm (Who, What, When, Where, and How), systematically mapping and unifying security practices across the full lifecycle, multiple stakeholder roles, and implementation tiers. Contribution/Results: We distill ten core security practices, identify critical infrastructure–specific coverage gaps in current standards, and develop a contextualized assessment checklist comprising 80 structured questions. The framework enables cross-organizational collaborative governance and advances a context-aware, integrated software supply chain security posture.

Addressing fragmented software supply chain security for critical infrastructureBridging gaps between existing frameworks and sector-specific requirementsDeveloping integrated security checklist for multi-stakeholder implementation

Internal Vulnerabilities, External Threats: A Grounded Framework for Enterprise Open Source Risk Governance

Oct 29, 2025
WY
Wenhao Yang
🏛️ Peking University | Bitergia | Huawei Technologies Co., Ltd.

Conventional open-source risk management overrelies on technical tools, failing to address systemic risks—including upstream “silent fixes,” community conflicts, and sudden license changes—resulting in governance blind spots. Method: This paper proposes a strategic open-source risk governance framework centered on the interaction between external threats and internal vulnerabilities, shifting from tactical response to proactive, strategic prevention. It innovatively introduces a Strategic Objective Matrix and a dual-risk taxonomy, yielding an “Object–Threat–Vulnerability–Mitigation” decision model; integrates grounded theory, strategic mapping, and capability-building principles to support organization-level governance decisions. Contribution/Results: Validated by three domain experts and applied in real-world case studies, the framework significantly enhances risk analytical capability and enables enterprises to establish a systematic, immunizing mechanism against open-source risks.

Addressing systemic open source risks beyond technical vulnerabilitiesDeveloping framework to connect external threats with internal vulnerabilitiesShifting from tactical risk management to holistic risk governance

A Systematic Approach to Estimate the Security Posture of a Cyber Infrastructure: A Technical Report

Aug 29, 2025
QS
Qishen Sam Liang
🏛️ USC Information Sciences Institute

Scientific research cyberinfrastructure (CI) faces unique challenges—including high collaboration requirements, component heterogeneity, and the absence of adaptable security assessment frameworks. To address these, we propose a mission-centric security posture assessment method: first, top-down identification of critical assets and unacceptable losses; second, construction of a security knowledge graph integrating system components, dependencies, and threat behaviors; and third, integration with directed attack graphs to quantify multi-hop attack paths from entry points to critical assets—enabling visualization of attacker-defender relationships and identification of security blind spots. Unlike conventional generic standards, our approach is the first to deeply couple mission-driven assessment, knowledge graphs, and attack graphs. It supports risk prioritization and generation of actionable defensive strategies, significantly enhancing the precision and effectiveness of CI security defense.

Addressing lack of practical security assessment frameworksEstimating security posture of collaborative cyber infrastructuresSystematically mapping adversary attack paths to critical assets

The Loss of Control Playbook: Degrees, Dynamics, and Preparedness

Nov 19, 2025
CS
Charlotte Stix
🏛️ Apollo Research

The field lacks a unified, operationally defined framework for AI “Loss of Control” (LoC), hindering rigorous safety analysis and governance. Method: We propose the first tiered LoC taxonomy and a socio-vulnerability evolution model, systematically characterizing three LoC pathways—Deviation, Bounded LoC, and Strict LoC—arising from objective misalignment or system failure. Innovatively, we introduce the Deployment-context, Affordance, and Permissions (DAP) external regulation framework, shifting focus from internal capability interventions to context-aware, deployable controls. Our approach integrates risk/threat modeling, pre-deployment testing, runtime monitoring, and multi-layered governance across the AI lifecycle. Contributions: (1) Quantifiable LoC severity criteria; (2) an early-warning pathway for societal vulnerability; (3) an immediately applicable DAP intervention framework; and (4) a “permanent hover” techno-governance co-design strategy. Together, these deliver a systematic, implementable foundation for advanced AI safety governance.

Developing a graded taxonomy for AI Loss of Control based on severity and persistenceModeling pathways to societal vulnerability from advanced AI systems causing harmProposing a preparedness framework focusing on extrinsic factors and governance measures

MISSION AWARE: Evidence-Based, Mission-Centric Cybersecurity Analysis

Dec 05, 2017
GB
Georgios Bakirtzis
🏛️ Télécom Paris | Institut Polytechnique de Paris | University of Virginia | Iowa State University | Virginia Commonwealth University

Traditional perimeter-based defenses fail against advanced persistent threats (APTs), compromising mission continuity. Method: This paper proposes a mission-success-oriented cybersecurity analysis framework. It introduces a novel hierarchical modeling approach integrating mission requirements, functional behaviors, and system architecture, supported by structured requirement elicitation, HAZOP hazard analysis, SysML modeling, and evidence-chain traceability to quantify attack impact pathways on mission objectives. Contribution/Results: The framework enables a paradigm shift from tactical defense to strategic resilience assessment, significantly improving identification accuracy of critical mission components and efficiency of protective resource allocation. Its capability for interpretable, impact-path modeling under APT scenarios is empirically validated across multiple defense information system prototypes.

It identifies components whose compromise destabilizes mission objectivesMission Aware addresses cyber-physical attacks on mission-critical systemsThe approach prioritizes vulnerabilities impacting mission requirements and assets

Latest Papers

What's happening recently
View more

A Systematic Mapping Study on Risks and Vulnerabilities in Software Containers

Dec 12, 2025
MS
Maha Sroor
🏛️ University of Jyvaskyla | University of Oulu

Container technologies are widely adopted, yet their full lifecycle entails significant security risks; existing software engineering literature lacks systematic, empirically grounded integration of container security knowledge. To address this gap, we conducted a systematic mapping study (SMS) complemented by bibliometric analysis and thematic coding across 129 empirical studies. Our work introduces the first structured, evidence-based taxonomy of security risks for containerized systems—identifying 23 core risk categories and vulnerabilities, explicating their root causes and impacts, and synthesizing reusable mitigation strategies. Additionally, we catalog 47 security practices and tools. The taxonomy enables cross-phase risk mapping—from development through deployment—and integrates fragmented knowledge into a coherent framework. It establishes a theoretical benchmark for container security research and delivers actionable, engineering-oriented guidance for practitioners.

Identifies security risks in container development and deploymentOrganizes knowledge on vulnerabilities across container lifecycleProposes mitigation techniques and security practices for containers

Offensive tool determination strategy R.I.D.D.L.E. + (C)

Nov 16, 2025
HE
Herman Errico
🏛️ Italian Association of Critical Infrastructures’ Experts

Conventional critical infrastructure risk assessments inadequately characterize deliberate threats, particularly regarding attacker tooling. Method: This paper proposes an embedded attack-tool identification strategy, introducing the first R.I.D.D.L.E.+C seven-dimensional analytical framework—encompassing Resistance, Intrusion Timing, Destruction Timing, Delay, Efficiency, Cost, and Concealment—to systematically integrate attack-tool characteristics and augment them with open-source intelligence (OSINT) for fine-grained, quantitative modeling. Contribution/Results: The approach shifts risk assessment from asset- or attacker-centric paradigms to treating attack tools as independent analytical units; significantly enhances detection of latent vulnerabilities; and delivers an actionable, forward-looking security decision-support framework. Experimental evaluation demonstrates substantial improvements in both precision and comprehensiveness of risk assessment, confirming its practical engineering applicability.

Analyzing intentional threats to critical infrastructure vulnerabilities through risk assessmentEvaluating threat variables using open-source intelligence for improved decision-makingIntroducing offensive tool characteristics as analytical parameters in security evaluation

Security Debt in Practice: Nuanced Insights from Practitioners

Jul 15, 2025
CB
Chaima Boufaied
🏛️ University of Calgary | Trent University | Prince Sultan University

This study addresses the ambiguity in recognizing security debt (SD), fragmented management practices, and insufficient cross-role communication—challenges exacerbated by delivery pressure and resource constraints in software development. Through semi-structured interviews with 22 practitioners from diverse countries and roles (development, security, operations), complemented by qualitative analysis grounded in both software engineering (SE) and information security (InfoSec) perspectives, the research systematically identifies SD root causes, propagation pathways, and trade-off mechanisms. It is the first to empirically reveal significant inter-role discrepancies in security risk perception, priority assessment, and tool adoption. The study proposes an integrated framework embedding the CIA triad (Confidentiality, Integrity, Availability) into each phase of the software development lifecycle (SDLC). Findings validate the necessity of enforcing consistent security policies, dynamically balancing resources, and enabling cross-level risk communication—providing empirical foundations and actionable pathways for systemic SD governance.

Communication of security risks within teams and to decision makersHow practitioners perceive and manage security debtsTools and strategies used to mitigate security debts

This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.

critical infrastructurecyber safetycyber-physical systems

This work addresses the weak isolation and difficulty in identifying security risks in Operational Technology (OT) environments, where container deployments often require elevated privileges. To tackle this challenge, the paper proposes Container Security Risk Ontology (CSRO), the first ontology-driven approach specifically designed for OT container security. CSRO integrates five key domains—adversarial behaviors, contextual assumptions, attack scenarios, risk assessment rules, and container security artifacts—to enable end-to-end formal modeling and automated reasoning from deployment metadata to quantified risk levels. The ontology is designed with modularity, reproducibility, cross-context interpretability, and seamless integration with deployment artifacts, allowing straightforward extension to host and organizational layers. A case study demonstrates CSRO’s effectiveness in automatically identifying security risks within hybrid IT/OT architectures.

container deploymentscontainer securityhybrid IT/OT architectures

Hot Scholars

SC

Stephen Casper

PhD student, MIT
AI safetyAI responsibilityred-teamingrobustness
LW

Laurie Williams

North Carolina State University, Computer Science, Distinguished Univ Prof, IEEE Fellow, ACM Fellow
Software EngineeringSoftware SecurityAgile Software DevelopmentEmpirical Software Engineering
VM

Vasilios Mavroudis

Research Scientist, Alan Turing Institute
Machine LearningSystems SecurityArtificial Intelligence
YA

Yasemin Acar

Paderborn University & The George Washington University