TRACE worksheet and reconstruction test
Cyber-Risk Decisions That Survive the Handoff
A cyber-risk decision survives a handoff when another qualified person can tell what triggered it, who had authority, which alternatives were considered, what evidence bounded the choice, and when it must be reopened. The receiver can disagree with the decision and still reconstruct it accurately.
Last updated:
Two-minute TRACE check
TRACE is a proposed CertArc method for recording the minimum context another qualified person needs to reconstruct a management decision. It is not an external standard or a substitute for local governance.
The emphasis on roles, evidence, review conditions, and risk communication is consistent with the management context in NIST Cybersecurity Framework (CSF) 2.0 and NIST IR 8286 Revision 1. Neither publication prescribes TRACE.
T
Trigger
Define the condition that requires a decision and the decision being made.
R
Responsibility
Name the authority and the roles needed to carry the decision through.
A
Alternatives
Record the credible options and the practical consequence of each.
C
Chain of evidence
Separate verified facts from estimates, assumptions, versions, and uncertainty.
E
Expiry
Set the date or observable event that requires the decision to be reopened.
TRACE worksheet · Version 1.0 · 7 August 2026
TRACE worksheet
Complete each field, then use your browser's Print command to retain a blank or completed working copy.
Proposed method by CertArc · certarc.com/security/cyber-risk-decision-handoff
Trigger
Define the condition that requires a decision and the decision being made.
- What changed or requires a choice?
- What decision or authorization is requested?
- What is in scope, and what is explicitly out of scope?
Responsibility
Name the authority and the roles needed to carry the decision through.
- Which role has decision authority?
- Who recommends, executes, verifies, and monitors?
- Who must be informed before action?
Alternatives
Record the credible options and the practical consequence of each.
- Which options were considered?
- What operational, risk, cost, and timing consequences matter?
- Why was the selected option preferred under the current constraints?
Chain of evidence
Separate verified facts from estimates, assumptions, versions, and uncertainty.
- Which evidence materially bounded the choice?
- Which facts were verified, and when?
- Which assumptions or uncertainties could change the decision?
- Where is the supporting evidence retained?
Expiry
Set the date or observable event that requires the decision to be reopened.
- What date or event triggers review?
- What closure condition ends the temporary decision?
- Who monitors the trigger and records the review?
Plain-text TRACE template
Select and copy this version into an existing decision, risk, change, or incident record.
T: Trigger Define the condition that requires a decision and the decision being made. - What changed or requires a choice? - What decision or authorization is requested? - What is in scope, and what is explicitly out of scope? Record: R: Responsibility Name the authority and the roles needed to carry the decision through. - Which role has decision authority? - Who recommends, executes, verifies, and monitors? - Who must be informed before action? Record: A: Alternatives Record the credible options and the practical consequence of each. - Which options were considered? - What operational, risk, cost, and timing consequences matter? - Why was the selected option preferred under the current constraints? Record: C: Chain of evidence Separate verified facts from estimates, assumptions, versions, and uncertainty. - Which evidence materially bounded the choice? - Which facts were verified, and when? - Which assumptions or uncertainties could change the decision? - Where is the supporting evidence retained? Record: E: Expiry Set the date or observable event that requires the decision to be reopened. - What date or event triggers review? - What closure condition ends the temporary decision? - Who monitors the trigger and records the review? Record:
Worked example
This hypothetical record separates a technical observation from an accountable management decision. It records temporary containment, final remediation, authority, evidence, assumptions, and explicit reopening conditions. It is an example of record quality, not a required treatment for every critical vulnerability.
T · Trigger
A vendor advisory and an authenticated scan confirm a critical vulnerability in the customer account service. The normal change window is six days away. The decision is whether to use an emergency change now or apply time-limited containment until a tested patch can enter the emergency window.
R · Responsibility
The business-service owner has treatment authority. Security engineering recommends controls, the platform team executes them, service assurance verifies the change, and the incident lead monitors exploitation signals and customer impact.
A · Alternatives
Options considered: immediate untested patching with outage risk; temporary access restriction and increased monitoring until an emergency window; service shutdown; or unbounded deferral. The owner selects temporary restriction and monitoring, followed by tested emergency remediation, because it reduces exposure without accepting an indefinite delay.
C · Chain of evidence
Verified: advisory version, affected build, authenticated scan result, exposed path, current maintenance schedule, rollback test status, and monitoring coverage. Assumptions: no known exploitation in the environment and the temporary restriction blocks the exposed path. Supporting records remain in the vulnerability, change, and incident systems.
E · Expiry
Reopen the decision at the earlier of the approved emergency window, evidence of attempted exploitation, failure of the temporary restriction, material customer impact, or a vendor update that changes the treatment. The incident lead monitors the triggers; the service owner records closure after remediation is verified.
Blind reconstruction test
This test asks whether the record transfers the decision, not whether the receiver endorses it.
- Select a completed decision record.
- Give it to a qualified reviewer who was not in the meeting.
- Withhold meeting notes and spoken context during the test.
- Ask the reviewer to reconstruct each TRACE field in plain language.
- Compare what the reviewer recovered with the meaning the decision owner intended to record.
The test borrows the general discipline of checking consistency across people. It is not the statistical measurement-system study described in ASQ: Gage Repeatability and Reproducibility.
Reconstruction scorecard
Mark one outcome for each field. Use notes to record missing context or a material difference between the owner's intended meaning and the receiver's reconstruction.
| TRACE field | Aligned | Partially aligned | Not recoverable | Notes |
|---|---|---|---|---|
| T · Trigger | ||||
| R · Responsibility | ||||
| A · Alternatives | ||||
| C · Chain of evidence | ||||
| E · Expiry |
T · Trigger
- Aligned
- Partially aligned
- Not recoverable
Notes
R · Responsibility
- Aligned
- Partially aligned
- Not recoverable
Notes
A · Alternatives
- Aligned
- Partially aligned
- Not recoverable
Notes
C · Chain of evidence
- Aligned
- Partially aligned
- Not recoverable
Notes
E · Expiry
- Aligned
- Partially aligned
- Not recoverable
Notes
Process measures
These four proposed measures make the calculation visible. They are not external benchmarks. Define material alignment, the sampling boundary, and acceptable performance for your own operating context before using them.
First-pass reconstruction yield
- Definition
- The share of sampled records that transfer all five TRACE fields materially without clarification.
- Calculation
- Sampled records with all five fields materially aligned without clarification ÷ sampled records.
- Data needed
- Sample boundary, field-by-field scores, and whether clarification occurred.
- Misuse warning
- Do not compare teams until they use the same definition of material alignment and sampling boundary.
Clarification load
- Definition
- The substantive follow-up needed before a receiver can act on or review a record.
- Calculation
- Count the substantive follow-up questions a receiver needs before acting on or reviewing the decision.
- Data needed
- Questions asked, the TRACE field involved, and whether the question blocked action.
- Misuse warning
- Do not reward fewer questions when receivers are discouraged from raising genuine uncertainty.
Trigger coverage
- Definition
- The share of sampled decisions that contain a specific reopening condition.
- Calculation
- Sampled decisions with a specific review date or observable reopening event ÷ sampled decisions.
- Data needed
- Sample boundary and the recorded expiry trigger for each decision.
- Misuse warning
- A vague phrase such as “review later” does not count as a specific trigger.
Stale-decision escape rate
- Definition
- The share of triggered decisions that continue to be acted on without a documented review.
- Calculation
- Decisions used after their expiry condition without documented review ÷ sampled decisions whose expiry condition occurred.
- Data needed
- Expiry events, actions after expiry, and documented review outcomes.
- Misuse warning
- Do not treat the measure as a universal benchmark or hide emergency exceptions; define the local rule first.
30-day pilot
Start with a bounded sample and one information-transfer problem. The pilot should be small enough to stop or revise without redesigning every risk workflow.
Week 1
Choose a small cross-section of completed decisions and define the sampling boundary, qualified reviewer, and meaning of material alignment.
Week 2
Map TRACE language to existing records, then run the first independent reconstructions without verbal briefings.
Week 3
Group material mismatches by the TRACE field that failed and correct one dominant information-transfer cause.
Week 4
Test a new sample, compare the process measures, and decide whether to adopt, revise, or stop the method.
For incident use, keep the minimum record proportionate to urgency and complete missing handoff detail within a locally defined interval. NIST SP 800-61 Revision 3 supports integrating incident response with cybersecurity risk management; it does not prescribe TRACE or a completion interval.
Limits and appropriate use
- TRACE is not a risk-acceptance method and does not determine the correct appetite or treatment.
- TRACE is not a statistical gage repeatability and reproducibility study.
- TRACE does not replace a risk register, incident record, approval workflow, or evidence repository.
- TRACE tests information transfer; it does not require the reviewer to endorse the decision.
- Routine preauthorized actions do not need to be recast as management decisions. In urgent incident work, teams may capture a minimum record first, then complete the handoff within an interval defined by their organization.
Questions about TRACE
Who should complete a TRACE record?
The person preparing or recording the decision should complete it with the decision authority and the roles responsible for execution, verification, and monitoring. Local governance should define who owns the final record.
Does TRACE replace a cybersecurity risk register?
No. A risk register tracks risks and treatments across time. TRACE records enough decision context for another qualified person to reconstruct a particular choice and its review trigger.
Can TRACE be used during an incident?
Yes, if the organization keeps the record proportionate to urgency. A minimum record can support immediate coordination, with missing handoff detail completed within an organization-defined interval.
Does the reconstruction reviewer need to agree with the decision?
No. The reviewer may disagree with the treatment and still reconstruct the trigger, authority, alternatives, evidence, and expiry accurately. The test evaluates transfer, not endorsement.
Is the TRACE reconstruction test a GR&R study?
No. It borrows the general discipline of checking consistency across people, but it is not a statistical measurement-system study and should not be reported as one.