The issues of inconsistent risk assessments and inadequate decision-making are every organization’s nightmare when determining the impact of cyber risk scenarios. Greater precision in defining them is the only solution to this growing challenge.
What then becomes important to ask is that where do assessments and decision-making fall short.
Some major perils include lack of actionable detail in drafted risk statements, dearth of consistent definitions regarding assets of the organization, threats, methods used by threat actors, and loss effects, and finally overburdened risk registers that cloud focus from critical threats. Thus, resulting in impairment of risk prioritisation and comparison.
A well-defined structure to this process becomes a crucial element for managing and defining these cyber risk scenarios. A well-curated taxonomy that labels identified risk elements can be of immense help here.
How can the taxonomy help?
FAIR taxonomy does all this while being a genuine guide to analysts for structuring cyber risk scenarios. It adds precision by segmenting the elements that make up a risk scenario. It does so by finding the following four core elements:
FAIR expresses this with a phrase to help understand the above-mentioned elemental breakup better.
“[Threat] impacts [asset] via [method], causing [effect(s)].”
This can be further simplified as;
A cybercriminal affects business data via phishing emails causing reputational damage.
These four core elements have been further broken down in the detailed version of the guide where a definition for each element with relevant examples has been supplemented for deeper understanding.
Since new developments are often evaluated with a pros-and-cons framework, the following benefits stand out. This includes:
Thus, this guide is a starting point for all those who work at the operational side of risk scenarios. This is relevant for security decision-makers, GRC (Governance, Risk and Compliance) practitioners, and executives responsible for cyber risk strategy.
This guide also becomes crucial for the industry in analysing and quantifying the cyber risks. Combined with a dedicated program that improves upon the risk quantification journey, this can serve as a rewarding model.
DSCI-FAIR Cyber Risk Quantification program can hence become a stepping stone in the journey to adopting FAIR principles and practices for better cyber risk management.
Offering groundbreaking quantitative risk analysis model, the industrial credibility program has helped professionals in bridging the gap between cybersecurity and their business objectives.
More details can be learned at: https://www.dsci.in/content/dsci-fair-cyber-risk-quantification
Note:
This blog is an adaptation from the FAIR Institute’s blog on Announcing a FAIR Taxonomy for Cyber Risk Scenarios
For more details, visit: https://www.fairinstitute.org/
Author: Mridushi Bose