A Cyber Manual Movement tool. The Value Chain Risk Institute is a member of the Cyber Manual Movement working group. This is the Annex VII (product cybersecurity risk assessment) companion to the Movement's CRA user-information manual template — the risk-assessment half of the pair, built in the Movement's established mode: VCRI provides the engine and drafting aids; the working group owns the scenario libraries and worked examples.
1 · Product model
The product with digital elements under assessment. In the full tool this pre-populates from a Manual Builder export (Annex II ↔ Annex VII loop); in this MVP, enter it directly.
2 · Threat scenarios
Generated, not blank-page: eight assumption-violation classes crossed with your interfaces produce candidate scenarios. Accept, edit, or discard. (Classes authored by VCRI; no text reproduced from paywalled standards.)
4 · Risk register & treatment
Feasibility × impact → risk. Choose a treatment per scenario. User-borne treatments emit Condition-of-Use candidates that flow back into the Annex II manual; manufacturer-borne ones become product security properties.
5 · Annex VII summary & Annex I trace
The assessment as a CRA-shaped summary. Each accepted risk can be traced to the Annex I essential requirement it justifies. Indicative, not a conformance claim.
A Cyber Manual Movement tool. Built by the Value Chain Risk Institute, a member of the Cyber Manual Movement working group, as the Annex VII companion to the Movement's CRA user-information manual template.
Value Chain Risk Institute · valuechainrisk.org/tara · CC BY 4.0 · Source on GitHub · Companion: /cra-manual-builder/ (Annex II) · /scorer/ (posture)
Methodology informed by ISO/SAE 21434-style TARA practice; all anchors authored originally. This tool makes no conformance determination.