This is the phase where the described metamodel has the least to offer in terms of support. Ultimately the determined risk levels can be added as attributes to various concepts, but such numeric representation of the concept of risk cannot be analyzed or condensed without an additional methodology (which our model does not support as of right now). However it is desirable to find a solution to this as the quantification of information security is one of the grand challenges in this domain. The modeling of assets, threats and vulnerabilities could allow for the description of risk propagation, sharing of risk amongst multiple assets or assets in a certain constellation.