TRACE worksheet and reconstruction test

Cyber-Risk Decisions That Survive the Handoff

A cyber-risk decision survives a handoff when another qualified person can tell what triggered it, who had authority, which alternatives were considered, what evidence bounded the choice, and when it must be reopened. The receiver can disagree with the decision and still reconstruct it accurately.

Last updated:

Use the TRACE worksheet

Two-minute TRACE check

TRACE is a proposed CertArc method for recording the minimum context another qualified person needs to reconstruct a management decision. It is not an external standard or a substitute for local governance.

The emphasis on roles, evidence, review conditions, and risk communication is consistent with the management context in NIST Cybersecurity Framework (CSF) 2.0 and NIST IR 8286 Revision 1. Neither publication prescribes TRACE.

T

Trigger

Define the condition that requires a decision and the decision being made.

R

Responsibility

Name the authority and the roles needed to carry the decision through.

A

Alternatives

Record the credible options and the practical consequence of each.

C

Chain of evidence

Separate verified facts from estimates, assumptions, versions, and uncertainty.

E

Expiry

Set the date or observable event that requires the decision to be reopened.

TRACE worksheet · Version 1.0 · 7 August 2026

TRACE worksheet

Complete each field, then use your browser's Print command to retain a blank or completed working copy.

Proposed method by CertArc · certarc.com/security/cyber-risk-decision-handoff

Trigger

Define the condition that requires a decision and the decision being made.

  • What changed or requires a choice?
  • What decision or authorization is requested?
  • What is in scope, and what is explicitly out of scope?

Responsibility

Name the authority and the roles needed to carry the decision through.

  • Which role has decision authority?
  • Who recommends, executes, verifies, and monitors?
  • Who must be informed before action?

Alternatives

Record the credible options and the practical consequence of each.

  • Which options were considered?
  • What operational, risk, cost, and timing consequences matter?
  • Why was the selected option preferred under the current constraints?

Chain of evidence

Separate verified facts from estimates, assumptions, versions, and uncertainty.

  • Which evidence materially bounded the choice?
  • Which facts were verified, and when?
  • Which assumptions or uncertainties could change the decision?
  • Where is the supporting evidence retained?

Expiry

Set the date or observable event that requires the decision to be reopened.

  • What date or event triggers review?
  • What closure condition ends the temporary decision?
  • Who monitors the trigger and records the review?

Plain-text TRACE template

Select and copy this version into an existing decision, risk, change, or incident record.

T: Trigger
Define the condition that requires a decision and the decision being made.
- What changed or requires a choice?
- What decision or authorization is requested?
- What is in scope, and what is explicitly out of scope?
Record:

R: Responsibility
Name the authority and the roles needed to carry the decision through.
- Which role has decision authority?
- Who recommends, executes, verifies, and monitors?
- Who must be informed before action?
Record:

A: Alternatives
Record the credible options and the practical consequence of each.
- Which options were considered?
- What operational, risk, cost, and timing consequences matter?
- Why was the selected option preferred under the current constraints?
Record:

C: Chain of evidence
Separate verified facts from estimates, assumptions, versions, and uncertainty.
- Which evidence materially bounded the choice?
- Which facts were verified, and when?
- Which assumptions or uncertainties could change the decision?
- Where is the supporting evidence retained?
Record:

E: Expiry
Set the date or observable event that requires the decision to be reopened.
- What date or event triggers review?
- What closure condition ends the temporary decision?
- Who monitors the trigger and records the review?
Record:

Worked example

This hypothetical record separates a technical observation from an accountable management decision. It records temporary containment, final remediation, authority, evidence, assumptions, and explicit reopening conditions. It is an example of record quality, not a required treatment for every critical vulnerability.

T · Trigger

A vendor advisory and an authenticated scan confirm a critical vulnerability in the customer account service. The normal change window is six days away. The decision is whether to use an emergency change now or apply time-limited containment until a tested patch can enter the emergency window.

R · Responsibility

The business-service owner has treatment authority. Security engineering recommends controls, the platform team executes them, service assurance verifies the change, and the incident lead monitors exploitation signals and customer impact.

A · Alternatives

Options considered: immediate untested patching with outage risk; temporary access restriction and increased monitoring until an emergency window; service shutdown; or unbounded deferral. The owner selects temporary restriction and monitoring, followed by tested emergency remediation, because it reduces exposure without accepting an indefinite delay.

C · Chain of evidence

Verified: advisory version, affected build, authenticated scan result, exposed path, current maintenance schedule, rollback test status, and monitoring coverage. Assumptions: no known exploitation in the environment and the temporary restriction blocks the exposed path. Supporting records remain in the vulnerability, change, and incident systems.

E · Expiry

Reopen the decision at the earlier of the approved emergency window, evidence of attempted exploitation, failure of the temporary restriction, material customer impact, or a vendor update that changes the treatment. The incident lead monitors the triggers; the service owner records closure after remediation is verified.

Blind reconstruction test

This test asks whether the record transfers the decision, not whether the receiver endorses it.

  1. Select a completed decision record.
  2. Give it to a qualified reviewer who was not in the meeting.
  3. Withhold meeting notes and spoken context during the test.
  4. Ask the reviewer to reconstruct each TRACE field in plain language.
  5. Compare what the reviewer recovered with the meaning the decision owner intended to record.

The test borrows the general discipline of checking consistency across people. It is not the statistical measurement-system study described in ASQ: Gage Repeatability and Reproducibility.

Reconstruction scorecard

Mark one outcome for each field. Use notes to record missing context or a material difference between the owner's intended meaning and the receiver's reconstruction.

TRACE fieldAlignedPartially alignedNot recoverableNotes
T · Trigger
R · Responsibility
A · Alternatives
C · Chain of evidence
E · Expiry

T · Trigger

  • Aligned
  • Partially aligned
  • Not recoverable

Notes

R · Responsibility

  • Aligned
  • Partially aligned
  • Not recoverable

Notes

A · Alternatives

  • Aligned
  • Partially aligned
  • Not recoverable

Notes

C · Chain of evidence

  • Aligned
  • Partially aligned
  • Not recoverable

Notes

E · Expiry

  • Aligned
  • Partially aligned
  • Not recoverable

Notes

Process measures

These four proposed measures make the calculation visible. They are not external benchmarks. Define material alignment, the sampling boundary, and acceptable performance for your own operating context before using them.

First-pass reconstruction yield

Definition
The share of sampled records that transfer all five TRACE fields materially without clarification.
Calculation
Sampled records with all five fields materially aligned without clarification ÷ sampled records.
Data needed
Sample boundary, field-by-field scores, and whether clarification occurred.
Misuse warning
Do not compare teams until they use the same definition of material alignment and sampling boundary.

Clarification load

Definition
The substantive follow-up needed before a receiver can act on or review a record.
Calculation
Count the substantive follow-up questions a receiver needs before acting on or reviewing the decision.
Data needed
Questions asked, the TRACE field involved, and whether the question blocked action.
Misuse warning
Do not reward fewer questions when receivers are discouraged from raising genuine uncertainty.

Trigger coverage

Definition
The share of sampled decisions that contain a specific reopening condition.
Calculation
Sampled decisions with a specific review date or observable reopening event ÷ sampled decisions.
Data needed
Sample boundary and the recorded expiry trigger for each decision.
Misuse warning
A vague phrase such as “review later” does not count as a specific trigger.

Stale-decision escape rate

Definition
The share of triggered decisions that continue to be acted on without a documented review.
Calculation
Decisions used after their expiry condition without documented review ÷ sampled decisions whose expiry condition occurred.
Data needed
Expiry events, actions after expiry, and documented review outcomes.
Misuse warning
Do not treat the measure as a universal benchmark or hide emergency exceptions; define the local rule first.

30-day pilot

Start with a bounded sample and one information-transfer problem. The pilot should be small enough to stop or revise without redesigning every risk workflow.

  1. Week 1

    Choose a small cross-section of completed decisions and define the sampling boundary, qualified reviewer, and meaning of material alignment.

  2. Week 2

    Map TRACE language to existing records, then run the first independent reconstructions without verbal briefings.

  3. Week 3

    Group material mismatches by the TRACE field that failed and correct one dominant information-transfer cause.

  4. Week 4

    Test a new sample, compare the process measures, and decide whether to adopt, revise, or stop the method.

For incident use, keep the minimum record proportionate to urgency and complete missing handoff detail within a locally defined interval. NIST SP 800-61 Revision 3 supports integrating incident response with cybersecurity risk management; it does not prescribe TRACE or a completion interval.

Limits and appropriate use

  • TRACE is not a risk-acceptance method and does not determine the correct appetite or treatment.
  • TRACE is not a statistical gage repeatability and reproducibility study.
  • TRACE does not replace a risk register, incident record, approval workflow, or evidence repository.
  • TRACE tests information transfer; it does not require the reviewer to endorse the decision.
  • Routine preauthorized actions do not need to be recast as management decisions. In urgent incident work, teams may capture a minimum record first, then complete the handoff within an interval defined by their organization.

Questions about TRACE

Who should complete a TRACE record?

The person preparing or recording the decision should complete it with the decision authority and the roles responsible for execution, verification, and monitoring. Local governance should define who owns the final record.

Does TRACE replace a cybersecurity risk register?

No. A risk register tracks risks and treatments across time. TRACE records enough decision context for another qualified person to reconstruct a particular choice and its review trigger.

Can TRACE be used during an incident?

Yes, if the organization keeps the record proportionate to urgency. A minimum record can support immediate coordination, with missing handoff detail completed within an organization-defined interval.

Does the reconstruction reviewer need to agree with the decision?

No. The reviewer may disagree with the treatment and still reconstruct the trigger, authority, alternatives, evidence, and expiry accurately. The test evaluates transfer, not endorsement.

Is the TRACE reconstruction test a GR&R study?

No. It borrows the general discipline of checking consistency across people, but it is not a statistical measurement-system study and should not be reported as one.