Risk register
Every record carries its source. Verified rows are real HERMES test evidence; findings are synthetic and fictional. Click a row for treatment detail and framework references. Click a column heading to sort.
| Identifier | Title | Severity | System | Accountable owner | Target date | Status | Source |
|---|
Key risk indicators
Computed live from the register against the modelled remediation policy, never hard-coded. Policy: severity-tiered service level agreements anchored on a 40-day application-vulnerability clock, maximum three rescan cycles, escalation on breach.
Service level agreement performance by severity
| Severity | Service level agreement | Open | Overdue | Closed within agreement |
|---|
Framework coverage
Real data. Each risk category maps to a MITRE ATLAS technique, an OWASP Top 10 for Large Language Model Applications (2025) entry and NIST AI Risk Management Framework subcategories, as encoded in the HERMES attack library. Test results are from the executed run; the findings column counts synthetic register items in the same category.
| Risk category | MITRE ATLAS | OWASP for Large Language Models | NIST AI Risk Management Framework | Tests run | Tests passed | Open findings |
|---|
Coverage of the MAP function is an acknowledged gap in the current test suite: HERMES exercises GOVERN, MEASURE and MANAGE subcategories, while system-context mapping activities sit upstream of adversarial testing. Stating what the evidence does not cover is part of the assurance method.
Escalations
Items breaching the modelled policy, ordered by days overdue. Escalation follows the defined path; each step is triggered by agreement breach, rescan exhaustion or critical severity ageing.
| Identifier | Title | Severity | Days overdue | Rescan cycles used | Escalated to | Treatment in progress |
|---|