By: Patrick Florer
Jeff, Thank you for saying out loud what I have thought ever since I heard of this “forumula”. ALE = ARO * SLE, on the other hand, really is a mathematical formula – first defined, as I recently...
View ArticleBy: Why Risk = Threat and Vulnerability and Impact « Behavioral Security
[...] 2010 Jay Jacobs Leave a comment Go to comments Jeff Lowder wrote up a thought provoking post, "Why the “Risk = Threats x Vulnerabilities x Impact” Formula is Mathematical Nonsense” and I wanted...
View ArticleBy: sriram vasudevan
Hi Jeff, It’s a nice article talks about the basic fundas of security and its really nice you have given a new dimension and meaning for the existing risk formula. I agree to that but if we deeply find...
View ArticleBy: Robb Reck
Jeff, I completely agree that formula is flawed. I have always believed more in the very basic Risk = Probability * Impact. The vulnerabilities and threats from the original formula would factor into...
View ArticleBy: Remington Winters
Jeff, I think your argument is deficient as it does not seem to take into account the fact that the equation is meant to be used within a subjective and qualitative framework such as the OWASP RRM...
View ArticleBy: alex
remmington, as much as I love owasp, rrm also breaks the fundamental laws of mathematics as we know them by performing math other than addition or subtraction on ordinal scales. In addition to what...
View ArticleBy: Henry
While that is true, in most cases, using R = TxVxI formula is the only practical way of quantifying something that is inherently difficult to quantify. It’s a management tool to aid decision making. In...
View ArticleBy: Phil Wilson
Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...
View ArticleBy: Ryburn Ross
Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...
View ArticleBy: Tom Olzak
[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...
View ArticleBy: Clint
hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk
View ArticleBy: Scott Palmer
Jeff, I stumbled on this posting in support of my argument that the formula that many depend on is complete nonsense! It amazes me how many rely/depend on this formula when they don’t realize the...
View ArticleBy: Roberto
very interesting discussion. My 2-cent corntibute is: in a number of standards the notion of risk is associated to a combination of impact and likelihood, may change some names but the concepts are...
View ArticleBy: Sabuz
I want to divided the concept into two individual parts Risks & Impact and to define this things for action plan, it should be formulated with this formula threats + vulnerabilities=Risk ≤ Impact...
View ArticleBy: Scott
The primary problem with any risk formula is the identification and quantification of likelihood. You have to have direct access to the potential adversary, and some relatively controversial...
View ArticleBy: Henry
While that is true, in most cases, using R = TxVxI formula is the only practical way of quantifying something that is inherently difficult to quantify. It’s a management tool to aid decision making. In...
View ArticleBy: Phil Wilson
Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...
View ArticleBy: Ryburn Ross
Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...
View ArticleBy: Tom Olzak
[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...
View ArticleBy: Clint
hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk
View Article