logo

Ensuring Risk Assessments have a (Business) Impact

ID: f72922af-e541-5a5e-94de-44008bad3b2c

STIX ID: report--f72922af-e541-5a5e-94de-44008bad3b2c

Feed Name: TrustedSec blog

Date Published: 2025-09-04

Date Updated: 2026-05-01

...
...

The article reviews existing risk frameworks (ISO31000, ISO27005, NIST SP800-30, OCTAVE, FAIR) and proposes a hybrid approach that enhances FAIR with additional variables and a 'What, Who, How' conversation—linking business-critical assets, likely adversaries, and technical adversary simulation—to produce more actionable qualitative, semi-quantitative, and quantitative risk assessments for executives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.