Appendix GThreats Risk Register
This document provides a consolidated record of key risks identified for the DeFi lending and borrowing dApp, categorized by severity and likelihood, and mapped to specific threat scenarios, vulnerabilities (CWEs), and impacted components within the platform. It functions as a central reference point for tracking the organization’s progress toward the risk mitigation objectives outlined in the security strategy.
Each risk is assigned a status to reflect its current treatment:
- In Progress: Active mitigation efforts are underway.
- Mitigated: Appropriate controls have been implemented and verified.
- Accepted: The risk has been acknowledged, with no immediate action planned.
Given the critical nature of many threat scenarios, all risks listed in this register are either actively being addressed or have already been successfully mitigated.
This register supports informed decision-making by security, engineering, and business stakeholders and ensures visibility and accountability across the risk management lifecycle.
| Threat scenario description | Impacted asset | Associated CWEs/CVEs | Overall threat scenario risk rating | Risk mitigation status |
|---|---|---|---|---|
| TS1 – Malicious actors targeting dApp’s mobile UI | Mobile UI | CWE-287 (improper authentication), CWE-359 (exposure of private information) | Critical | Mitigated |
| TS2 – Threats targeting digital wallets | Digital wallet | CWE-287 (improper authentication), CWE-190 (integer overflow) | Critical | Mitigated |
| TS3 – Threats to distributed identity systems ... |
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access