Chapter 6

Analysis Process

Abstract

In this chapter, the authors review the process by which one conducts a Factor Analysis of Information Risk (FAIR) risk analysis. A review of the tool requirements is given (those items in addition to the ontology). A brief review of the licensing requirements and open source options for analysis tools is covered. A review of the scenario building technique, how to model assets, threat communities, threat types, and effects is discussed. A review of the necessity of expert estimation and stochastic modeling tools is given. Last, the authors cover the concept of levels of abstraction and show how they apply to various FAIR risk factors.

Keywords

Abstraction; Analysis process; Applied risk analysis; Modeling; Scenarios ...

Get Measuring and Managing Information Risk now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.