Here's a sampling of FAIR Institute member contributions to the community in 2022:
David Severski, Senior Security Data Scientist, Cyentia Institute, speaking on FAIRCON22 panel discussion Scaling a Quantitative Risk Management Program.
“In a lot of the conversation I’ve seen over the years is, there really wasn’t any rhyme or reason for how much cyber insurance we had. Someone just made a decision, likely the CISO, maybe someone in finance.”
“Now, with the FAIR standard, we can model specific scenarios and manage those risks in different ways. We can keep investing to add more controls and keep that risk down, or in some cases, move that bar up and get more transfer coverage with insurance.”
Jeff Norem, Deputy CISO, Freddie Mac, Meet a Member Interview.
A key part of FAIR development in your organization must be data independence. Network with the cybersecurity disciplines across your organization and use your goodwill to gain access to the troves of existing data on dashboards, logs, and SharePoint repositories.
Additionally, being included on various automated distribution lists and alerts can also position your team to gather important data without mucking up stakeholder calendars.
Caleb Juhnke, Senior Information Security Engineer (Cyber Risk Quantification), Equinix writing in the blog post 3 Quick Steps for FAIR Program Maturity.
Join the community is to sign up for a FAIR Institute Contributing Membership.
Loss Event Chain of Events from the FAIR Controls Analytics Model (FAIR-CAM™). For more detail, click to see the entire chart.
Raksha Shenoy, Information Security Engineer (Cyber Risk Quantification) at Equinix writing in the blog post Identifying the Right Risk Scenarios to Measure with FAIR
“Compliance is going to radically change. An assessor comes in and asks does the control exist and is it functioning the way it’s supposed to? Now we know. We can actively measure and document if that control is doing what it supposed to do. Now when we get that audit finding we can answer if it is really a big deal or something we can work on in the next fiscal year”
Drew Brown, Information System Security Developer, FAA, at the FAIRCON22 Panel Mapping Leading Control Frameworks to FAIR-CAM.