Skip to content

Latest commit

 

History

History
83 lines (60 loc) · 4.19 KB

File metadata and controls

83 lines (60 loc) · 4.19 KB

Risk Analysis Methods

Structured approaches to identifying, analyzing, and quantifying cybersecurity and enterprise risks.

FAIR (Factor Analysis of Information Risk)

FAIR Institute Resources

ISO 27005 & FAIR

FAIR Tools & Libraries

Quantitative Risk Analysis

Tools & Frameworks

Research

Qualitative Risk Analysis

Binary Risk Assessment (BRA)

Risk Management Experts & Organizations

Hubbard Research

Cyentia Institute

SRA (Society for Risk Analysis)

Calibration & Probabilistic Thinking

Improving Risk Management Comparisons and Decisions

SIRACon 2012: Tony Cox - Improving Risk Management Comparisons

  • Advanced critique of risk matrices, scoring formulas, and ranking methods
  • Demonstrates how standard rating/scoring methods often perform worse than random decision-making
  • Proposes quantitative optimization models as superior alternatives
  • Practical examples from information security, enterprise risk, and terrorism risk analysis
  • Key insight: Better risk reduction at lower cost through mathematical optimization

Cyentia Institute - IRIS Study (Information Risk Insights Study)

IRIS 20/20 - Cyentia Institute

  • 10 years of historical cyber incident data analysis
  • Measures frequency and cost of actual cyber incidents
  • Provides evidence-based data for risk assessment beyond "FUD" (Fear, Uncertainty, Doubt)
  • Supports quantitative risk modeling with empirical data

Decision Science Foundation

If risk assessments exist to facilitate informed decision-making, understanding the science behind decision-making becomes essential. Decision science principles should inform how we: