Chapter 3

The FAIR Risk Ontology

Abstract

This chapter gives a detailed look at the Factor Analysis of Information Risk (FAIR) risk analysis ontology. It gives the reader an understanding of the terms used in FAIR, such as Threat Event Frequency, Contact Frequency, Probability of Action, Vulnerability, Threat Capability, Difficulty (also known as Control Strength or Resistance Strength), Loss Event Frequency, Primary Loss Magnitude, Secondary Loss Event Frequency, Secondary Loss Magnitude, and Secondary Risk. The chapter also details some of the challenges associated with these terms in how they are used in the security and risk community at large. Lastly, the chapter concludes with some guidance about how to apply these terms and concepts to scenarios ...

Get Measuring and Managing Information Risk now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.