SlideShare a Scribd company logo
Quantifying Information Risk
An Introduction to Open FAIR
“When you can measure what you are speaking
about and express it in numbers, you know
something about it.” - Lord Kelvin
Apolonio “Apps” Garcia
Founder/CEO HealthGuard
John Zuziak
CISO Univ of Louisville Hospital
@appsgarcia @johnzuziak
Disclaimer: We are not lawyers. This is not legal advice. Our opinions are ours;
not our employers, or parents, or wives.
Introduction to Open FAIR
How Boards Feel About Security
Reports
Introduction to Open FAIR
85% believe that IT and security
execs need to improve the way they
report
54% feel the information is
too technical
59% say there is a good chance IT and
security executives will lose their job
Introduction to Open FAIR
Reports with
understandable language
Quantitative information about
cyber risks
Progress that has been
and is being made to
address the company’s
cyber risk
Introduction to Open FAIR
Introduction to Open FAIR
Essentially, all
models are wrong,
but some are
useful.
- George E. P. Box
NIST 800-30r1
Source: NIST 800-30r1 – Guide for Conducting Risk Assessments
Analysis Methods
1.Qualitative
2.Semi-Quantitative
3.Quantitative
Source: NIST 800-30r1 – Guide for Conducting Risk Assessments
Qualitative Analysis
Semi-Quantitative Analysis
Quantitative Analysis
Open
FAIR
What is FAIR?
Factor Analysis of Information Risk
Published by Jack Jones in 2005
Adopted by the Open Group in 2014
● Risk Taxonomy Standard
● Risk Analysis Standard
Causes of Bad Analysis
● Bad models
● Bad estimates and measurements
● Poorly defined scope, scenarios
● Poorly defined measurement scales
● Math on ordinal scales
● Cognitive biases
Loss
Magnitude
Risk
Loss Event
Frequency
The probable frequency and
probable magnitude of loss.
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Threat Event
Frequency
Risk
Vulnerability
Contact
Frequency
Probability
of Action
Threat
Capability
Resistance
Strength
Loss Event
Frequency
Loss
Magnitude
Secondary
Loss Factors
Risk
Primary Loss
Factors
Organizational
Loss Factors
External Loss
Factors
Asset Loss
Factors
Threat Loss
Factors
Loss Event
Frequency
Loss
Magnitude
Secondary
Loss Factors
Risk
Primary Loss
Factors
Organizational
Loss Factors
External Loss
Factors
Asset Loss
Factors
Threat Loss
Factors
Forms of Loss
● Productivity
● Response
● Replacement
● Fines/Judgement
● Competitive Advantage
● Reputation
Loss Event
Frequency
Loss
Magnitude
Secondary
Loss Factors
Risk
Primary Loss
Factors
Organizational
Loss Factors
External Loss
Factors
Asset Loss
Factors
Threat Loss
Factors
Case Study
Auditors report lack of laptop
encryption is a “high risk” issue.
Encryption will require a $200-250K
investment.
CFO wants to know if this is worth
the investment.
Case Study
Loss Event Frequency
Min
(95% CI)
Most
Likely
Max
(95% CI)
LEF 0 1 5
Case Study
Primary Loss Magnitude
Min
(95% CI)
Most
Likely
Max
(95% CI)
Replacement
Costs
$1,200 $1,750 $2,500
Response
Costs
$2,500 $10K $75K
Case Study
Secondary Loss Magnitude
Min
(95% CI)
Most
Likely
Max
(95% CI)
Response
Costs
$5K $25K $1M
Fines /
Judgement
$0 $0 $10M
Case Study
Case Study
You are here
www.healthguardsecurity.com/openfair
@appsgarcia
agarcia@healthguardsecurity.com
513.549.4272
Apolonio “Apps” Garcia John Zuziak
Sanitized version of slidedeck will be available at:
www.healthguardsecurity.com/blog
@johnzuziak
john.zuziak@ulh.org
859.240.7582
Follow us: @healthguardsec

More Related Content

PPTX
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
PDF
Introduction to FAIR Risk Methodology – Global CISO Forum 2019 – Donna Gall...
PPTX
Introduction to FAIR - Factor Analysis of Information Risk
PDF
How To Present Cyber Security To Senior Management Complete Deck
PDF
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
PPTX
Cyber Security Standards Compliance
PPTX
Cyber threat Intelligence and Incident Response by:-Sandeep Singh
PDF
Cybersecurity risk management 101
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
Introduction to FAIR Risk Methodology – Global CISO Forum 2019 – Donna Gall...
Introduction to FAIR - Factor Analysis of Information Risk
How To Present Cyber Security To Senior Management Complete Deck
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cyber Security Standards Compliance
Cyber threat Intelligence and Incident Response by:-Sandeep Singh
Cybersecurity risk management 101

What's hot (20)

PPTX
QRadar, ArcSight and Splunk
PPTX
Key risk indicators shareslide
PPTX
Third-Party Risk Management: Implementing a Strategy
PPTX
Iso27001 Risk Assessment Approach
PDF
Segregation of Duties and Continuous Delivery
PDF
Cyber threat intelligence ppt
PDF
ISO 27005 Risk Assessment
PDF
Risk Identification PowerPoint Presentation Slide
PDF
SOC Architecture - Building the NextGen SOC
PPT
Asset, Vulnerability, Threat, Risk & Control
PDF
Security operations center 5 security controls
PDF
Cybersecurity Roadmap Development for Executives
PDF
Risk Management Overview Powerpoint Presentation Slides
PDF
Threat Intelligence 101 - Steve Lodin - Submitted
PDF
Dealing with Information Security, Risk Management & Cyber Resilience
PPTX
Risk indicators
PDF
FireEye Solutions
PDF
VAPT Services by prime
PDF
Threat Modeling Basics with Examples
QRadar, ArcSight and Splunk
Key risk indicators shareslide
Third-Party Risk Management: Implementing a Strategy
Iso27001 Risk Assessment Approach
Segregation of Duties and Continuous Delivery
Cyber threat intelligence ppt
ISO 27005 Risk Assessment
Risk Identification PowerPoint Presentation Slide
SOC Architecture - Building the NextGen SOC
Asset, Vulnerability, Threat, Risk & Control
Security operations center 5 security controls
Cybersecurity Roadmap Development for Executives
Risk Management Overview Powerpoint Presentation Slides
Threat Intelligence 101 - Steve Lodin - Submitted
Dealing with Information Security, Risk Management & Cyber Resilience
Risk indicators
FireEye Solutions
VAPT Services by prime
Threat Modeling Basics with Examples
Ad

Similar to Introduction to Open FAIR (20)

PPTX
Crash Course: Managing Cyber Risk Using Quantitative Analysis
PPTX
Economically driven Cyber Risk Management
DOCX
Risk Management Insight FAIR(FACTOR AN.docx
DOCX
Risk Management Insight FAIR(FACTOR ANA.docx
PPTX
Information Security Risk Quantification
DOCX
Risk Management Insight FAIR(FACTOR AN.docx
DOCX
Risk Management Insight FAIR(FACTOR AN.docx
DOCX
Risk Management Insight FAIR(FACTOR ANA
DOCX
Risk Management Insight FAIR(FACTOR AN.docx
DOCX
Risk Management Insight FAIR(FACTOR ANA.docx
PPTX
Information systems risk assessment frame workisraf 130215042410-phpapp01
DOCX
4Brian DennisonJohn DensonIT454 -1504B-01Mon, 121415.docx
DOCX
Risk Management Insight FAIR(FACTOR AN.docx
PPTX
Assessing Quality in Cyber Risk Forecasting
PDF
Risk Analysis Webinar
PPTX
PPTX
Risk Analysis for Dummies
PDF
Quantifying Cyber Risk
PPTX
Reducing subjectivity in qualitative risk assessments
PPTX
OWASP Risk Rating Methodology.pptx
Crash Course: Managing Cyber Risk Using Quantitative Analysis
Economically driven Cyber Risk Management
Risk Management Insight FAIR(FACTOR AN.docx
Risk Management Insight FAIR(FACTOR ANA.docx
Information Security Risk Quantification
Risk Management Insight FAIR(FACTOR AN.docx
Risk Management Insight FAIR(FACTOR AN.docx
Risk Management Insight FAIR(FACTOR ANA
Risk Management Insight FAIR(FACTOR AN.docx
Risk Management Insight FAIR(FACTOR ANA.docx
Information systems risk assessment frame workisraf 130215042410-phpapp01
4Brian DennisonJohn DensonIT454 -1504B-01Mon, 121415.docx
Risk Management Insight FAIR(FACTOR AN.docx
Assessing Quality in Cyber Risk Forecasting
Risk Analysis Webinar
Risk Analysis for Dummies
Quantifying Cyber Risk
Reducing subjectivity in qualitative risk assessments
OWASP Risk Rating Methodology.pptx
Ad

Recently uploaded (20)

PDF
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
PDF
NEW - FEES STRUCTURES (01-july-2024).pdf
PPTX
Principles of Marketing, Industrial, Consumers,
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
Cours de Système d'information about ERP.pdf
PDF
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
PPTX
Slide gioi thieu VietinBank Quy 2 - 2025
PPTX
Sales & Distribution Management , LOGISTICS, Distribution, Sales Managers
PDF
IFRS Notes in your pocket for study all the time
PPTX
sales presentation، Training Overview.pptx
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PPTX
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
PDF
Solaris Resources Presentation - Corporate August 2025.pdf
PDF
THE COMPLETE GUIDE TO BUILDING PASSIVE INCOME ONLINE
PDF
1911 Gold Corporate Presentation Aug 2025.pdf
PPTX
Slide gioi thieu VietinBank Quy 2 - 2025
PPTX
Astra-Investor- business Presentation (1).pptx
PPTX
operations management : demand supply ch
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
NEW - FEES STRUCTURES (01-july-2024).pdf
Principles of Marketing, Industrial, Consumers,
Ôn tập tiếng anh trong kinh doanh nâng cao
Cours de Système d'information about ERP.pdf
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
Slide gioi thieu VietinBank Quy 2 - 2025
Sales & Distribution Management , LOGISTICS, Distribution, Sales Managers
IFRS Notes in your pocket for study all the time
sales presentation، Training Overview.pptx
2025 Product Deck V1.0.pptxCATALOGTCLCIA
TRAINNING, DEVELOPMENT AND APPRAISAL.pptx
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
Solaris Resources Presentation - Corporate August 2025.pdf
THE COMPLETE GUIDE TO BUILDING PASSIVE INCOME ONLINE
1911 Gold Corporate Presentation Aug 2025.pdf
Slide gioi thieu VietinBank Quy 2 - 2025
Astra-Investor- business Presentation (1).pptx
operations management : demand supply ch

Introduction to Open FAIR