In the second part of our blog series, we will focus on the third line of defense, internal audit, the types of data it can provide to contribute to a FAIR risk, and how it can benefit from adopting FAIR analysis in the risk quantification process.
Enhancing the 3 Lines of Defense with FAIR Risk Analysis (Part 2: Third Line)
[fa icon="calendar'] May 1, 2023 9:00:00 AM / by Michael Smilanich posted in Risk Management, FAIR Risk Model
Enhancing the Three Lines of Defense in Risk Management with FAIR Risk Analysis (Part 1: First & Second Lines)
[fa icon="calendar'] Apr 25, 2023 8:15:00 AM / by Michael Smilanich posted in Risk Management, FAIR Risk Model
In the world of risk management, the traditional Three Lines of Defense model has been widely adopted to mitigate and manage risks effectively. However, many organizations are still grappling with the process of communication
Create a Forward-Looking Risk Register to Anticipate Supply Chain Attacks - Part 2 of 'Modeling the Vulnerability du Jour'
[fa icon="calendar'] Apr 6, 2023 10:08:43 AM / by Tony Martin-Vegue posted in Risk Management, Member Content
With supply-chain attacks very much in the news – see the Apache Log4j vulnerability or the 3CX VoIP software compromise – we’re bringing back into view this post by FAIR thought leader Tony Martin-Vegue on how to leverage a risk register to prepare for emerging risks.
'Risk Appetite' vs. 'Risk Tolerance'. What’s the Difference?
[fa icon="calendar'] Feb 7, 2023 4:49:00 PM / by FAIR Institute Staff posted in FAIR, Risk Management
The terms “risk appetite” and its close cousin “risk tolerance” are often poorly understood, very rarely used to good effect, and commonly used interchangeably.
The Good News: World Economic Forum Finds CISOs and Boards Talking More
[fa icon="calendar'] Jan 19, 2023 8:39:28 AM / by Jeff B. Copeland posted in Risk Management
If you want to know what your board directors are hearing about cybersecurity, you’ll probably get a good idea from the research by the World Economic Forum, host of the Davos Conference
Academic Study Uncovers How Legal Privilege Undermines Cybersecurity
[fa icon="calendar'] Sep 13, 2022 10:52:00 AM / by Jeff B. Copeland posted in Risk Management
"In their zeal to preserve the confidentiality of incident response efforts, lawyers frequently undermine the long-term cybersecurity of both their clients and society more broadly.”
Dos and Don’ts of Using CVSS Scores in Cyber Risk Management
[fa icon="calendar'] May 24, 2022 2:12:25 PM / by Jeff B. Copeland posted in Risk Management
CVSS scores are widely used – and widely mis-used – in cyber risk management. The Common Vulnerability Scoring System serves as a valuable alert system to point defenders to weaknesses in their defenses. But because CVSS scoring is numeric, it is often confused as quantitative cyber risk analysis
Analyzing Privacy Risk Using FAIR
[fa icon="calendar'] Apr 5, 2022 6:08:00 PM / by R. Jason Cronk posted in Risk Management, Member Content
When I saw Jack Jones present on FAIR™ at an IANS Research Forum several years ago, it was like a light bulb went off in my head. I immediately ordered the FAIR book
CRQ For All: Introducing My Cyber Risk Benchmark from RiskLens (Sponsored Post)
[fa icon="calendar'] Mar 14, 2022 6:00:00 AM / by James Graham posted in Risk Management
Every day at RiskLens, we talk to organizations of all shapes, sizes, industries and levels of maturity about our mission to make cyber risk quantification (CRQ) and Factor Analysis of Information Risk (FAIR™) faster and easier for their organizations to adopt and implement.
4 Ways FAIR Cyber Risk Analysis Saves Money
[fa icon="calendar'] Mar 2, 2022 5:13:31 PM / by Jeff B. Copeland posted in FAIR, Risk Management
By quantifying cyber risk in financial terms, Factor Analysis of Information Risk (FAIR™) brings a bottom-line focus to budgeting and spending decisions