Threats considered for this asset- T-1Abnormal use of the scoring interface by an authorised operatorapplicable
- T-2Espionage of the model inputs in transitapplicable
- T-3Modification of the training corpusset aside
- T-4Loss of the candidate export fileapplicable
- T-5Overload of the scoring serviceset aside
Threat path — who, how, what they exploitAn operator with standing access to the scoring interface reads and reuses comparative scores outside the recruitment decision they were produced for — the interface exposes the ranking to every recruiter in the unit, and nothing records what was consulted.
Measures applied- MES-2Role-restricted access to scores, reviewed quarterly
- MES-7Export blocked outside the applicant-tracking system
Inherent risk, then residual
Likelihood →Severity ↑
Inherent — before measures Residual — after MES-2, MES-7
Residual riskNot acceptedA corrective action is required before the assessment can be recorded — an unacceptable risk with no treatment is refused.