Ensuring Risk Assessments have a (Business) Impact
ID: f72922af-e541-5a5e-94de-44008bad3b2c
STIX ID: report--f72922af-e541-5a5e-94de-44008bad3b2c
Feed Name: TrustedSec blog
The article reviews existing risk frameworks (ISO31000, ISO27005, NIST SP800-30, OCTAVE, FAIR) and proposes a hybrid approach that enhances FAIR with additional variables and a 'What, Who, How' conversation—linking business-critical assets, likely adversaries, and technical adversary simulation—to produce more actionable qualitative, semi-quantitative, and quantitative risk assessments for executives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
