${taskforce.name} Avatar
  1. OMG Task Force

Risk Analysis and Assessment Modeling Language (RAAML) 1.2 RTF — Open Issues

Open Closed All
Issues not resolved

Issues Descriptions

Fix Editorial Errors

  • Key: RAAML12-26
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    Fix editorial errors identified from Architecture Board Review conducted by Harlen Dean.

    • Front page has: http://www.omg.org/spec/RAAML/, I believe now everything should be https and not http. The above link does get redirected to https, so not a major issue.

    • From the official page one and all subsequent pages (page 13 of PDF) the footer is incorrect. It still says: Risk Analysis and Assessment Modeling Langauge (RAAML), v1.0 should be ‘v1.1 Beta 2’. Also, ‘Language’ is spelled incorrectly.

    • Multiple spelling errors were found:
    Incorrect Correct
    reliabiltiy reliability
    avaliability availability
    probablity probability
    probablity desnity probability density
    distribtuion distribution
    distirbution distribution
    propbability probability
    compelement complement
    paraemter / parameer parameter
    shapre shape
    equiavlent equivalent

    • In section HomogeneousKofNCalculation, below the figure, it says: k ou tof n system reliability or availability, should be k out of n system reliability or availability

    • Section 7.3.1 and 7.3.2 has Highway Driving Straight as Speed mentioned 3 times, should ‘at speed’.

    • Minor point, probably doesn’t need to be changed, but some images (not many) which have a grey grading on the objects are slightly difficult to read, the plain white objects are better for people with compromised vision:

    RAAML12-2 – Assumption image in SVG zip file looks incorrect.
    Zip file compared to Image in documents ptc-26-04-1

    RAAML12-11 – ProcessModelFlaw is still mentioned in section 10.6.1, page 184 (page 196 of pdf).

  • Reported: RAAML 1.1b1 — Wed, 27 May 2026 18:53 GMT
  • Updated: Wed, 27 May 2026 18:53 GMT

Revise STPA example documentation

  • Key: RAAML12-24
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    Revise the STPA example documentation to include usages for STPA-sec and to reflect errors corrected in the latest specification.

  • Reported: RAAML 1.1b1 — Fri, 24 Apr 2026 12:56 GMT
  • Updated: Mon, 4 May 2026 00:52 GMT
  • Attachments:
    • STPA-Sec Example.docx 2.21 MB (application/vnd.openxmlformats-officedocument.wordprocessingml.document)

Vulnerability is not currently stereotyped as Vulnerability, and is not marked as Abstract,

  • Key: RAAML12-15
  • Status: open   Implementation work Blocked
  • Source: MITRE ( Ms. Mary Tolbert)
  • Summary:

    The issue is that Vulnerability is not currently stereotyped as Vulnerability, and is not marked as Abstract, which puts it out of alignment with the other RAAML library elements. To resolve this, the ticket calls for stereotyping it as Vulnerability and marking it as abstract. This change should help ensure consistency with Factors and Limitations in the STPA Loss Scenario

  • Reported: RAAML 1.1 — Tue, 24 Mar 2026 13:54 GMT
  • Updated: Mon, 4 May 2026 00:52 GMT
  • Attachments:

Weakness is not stereotyped as Weakness, and is not marked as Abstract and must be made abstract for consistency

  • Key: RAAML12-14
  • Status: open   Implementation work Blocked
  • Source: MITRE ( Ms. Mary Tolbert)
  • Summary:

    The issue is that Weakness is not currently stereotyped as Weakness, and is not marked as Abstract, which puts it out of alignment with the other RAAML library elements. To resolve this, the ticket calls for stereotyping it as Weakness and marking it as abstract. This change should help ensure consistency with Factors and Limitations in the STPA Loss Scenario.

  • Reported: RAAML 1.1 — Tue, 24 Mar 2026 13:52 GMT
  • Updated: Mon, 4 May 2026 00:52 GMT
  • Attachments:

ProcessModelFlaw is not marked as Abstract and the name needs to be changed

  • Key: RAAML12-13
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    ProcessModelFlaw is not marked as Abstract. It must be abstract consistent with the other RAAML library elements. In addition the name ProcessModelFlaw is causing confusion and should be called ControlFlaw to be consistent with the Undesired Control Action and Control Structure.

  • Reported: RAAML 1.1 — Mon, 23 Mar 2026 13:42 GMT
  • Updated: Mon, 4 May 2026 00:52 GMT

ProcessModelFlaw is not marked as Abstract and the name needs to be changed


Add example for usage of RAAML for security


Add FHA section to Examples document


Add Functional Hazard Assessment (FHA) method to RAAML


Add stereotype for Vulnerability

  • Key: RAAML12-22
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    The Vulnerability element is stereotyped by a generic <<Situation>> stereotype and there is no dedicated <<Vulnerability>> stereotype. To resolve this add a stereotype for Vulnerability. This change should help ensure consistency with Factors and Limitations in the STPA Loss Scenario

  • Reported: RAAML 1.1 — Mon, 13 Apr 2026 12:51 GMT
  • Updated: Mon, 13 Apr 2026 13:03 GMT

Add stereotype for Weakness

  • Key: RAAML12-23
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    The Weakness element is stereotyped by a generic <<Situation>> stereotype and there is no dedicated <<Weakness>> stereotype. To resolve this, the ticket calls for adding a stereotype for Weakness. This change should help ensure consistency with Factors and Limitations in the STPA Loss Scenario.

  • Reported: RAAML 1.1 — Mon, 13 Apr 2026 12:58 GMT
  • Updated: Mon, 13 Apr 2026 13:02 GMT

Add ProcessModel and ControlAlgorithm stereotypes to STPA Profile

  • Key: RAAML12-18
  • Status: open   Implementation work Blocked
  • Source: MITRE ( Ms. Mary Tolbert)
  • Summary:

    The issue is that ProcessModel and ControlAlgorithm are not currently stereotypes in the STPA profile, but is required to accurately model a STPA Control Structure.

  • Reported: RAAML 1.1 — Tue, 24 Mar 2026 15:52 GMT
  • Updated: Wed, 8 Apr 2026 15:36 GMT

Threat should also be a subtype of Limitation-Factor

  • Key: RAAML12-17
  • Status: open   Implementation work Blocked
  • Source: MITRE ( Ms. Mary Tolbert)
  • Summary:

    The issue is that Threat is not currently considered as a Limitation-Factor, which is necessary in creating STPA Loss Scenarios. To resolve this, the ticket calls for making Threat a subtype of Limitation.

  • Reported: RAAML 1.1 — Tue, 24 Mar 2026 14:02 GMT
  • Updated: Wed, 8 Apr 2026 15:35 GMT

Threat is not stereotyped as Threat, and must be stereotyped for consistency

  • Key: RAAML12-16
  • Status: open   Implementation work Blocked
  • Source: MITRE ( Ms. Mary Tolbert)
  • Summary:

    The issue is that Threat is not currently stereotyped as Threat, which puts it out of alignment with the other RAAML profile elements. To resolve this, the ticket calls for stereotyping it as Threat.

  • Reported: RAAML 1.1 — Tue, 24 Mar 2026 13:58 GMT
  • Updated: Wed, 8 Apr 2026 15:35 GMT

Revise .xmi files to represent addition of FHA method

  • Key: RAAML12-9
  • Status: open  
  • Source: Ford Motor Company ( Mr. Kyle Post)
  • Summary:

    Revise the associated RAAML .xmi files to represent the changes made in the specification to add the new FHA method

  • Reported: RAAML 1.1b1 — Fri, 30 Jan 2026 21:27 GMT
  • Updated: Wed, 11 Feb 2026 00:23 GMT
  • Attachments:

ARP 4751 doesn't exist

  • Key: RAAML12-1
  • Status: open  
  • Source: RTX ( Mr. Andrew Muxen)
  • Summary:

    I suspect that this is a typo. I don't think that ARP4751 exists BUT ARP4761 exists. Review and make sure we are referencing the correct standard.

  • Reported: RAAML 1.1b1 — Wed, 16 Oct 2024 14:38 GMT
  • Updated: Wed, 11 Feb 2026 00:23 GMT