Quantcast
Channel: Comments on: Why the “Risk = Threats x Vulnerabilities x Impact” Formula is Mathematical Nonsense
Browsing all 36 articles
Browse latest View live

By: Patrick Florer

Jeff, Thank you for saying out loud what I have thought ever since I heard of this “forumula”. ALE = ARO * SLE, on the other hand, really is a mathematical formula – first defined, as I recently...

View Article


By: Why Risk = Threat and Vulnerability and Impact « Behavioral Security

[...] 2010 Jay Jacobs Leave a comment Go to comments Jeff Lowder wrote up a thought provoking post, "Why the “Risk = Threats x Vulnerabilities x Impact” Formula is Mathematical Nonsense” and I wanted...

View Article


By: sriram vasudevan

Hi Jeff, It’s a nice article talks about the basic fundas of security and its really nice you have given a new dimension and meaning for the existing risk formula. I agree to that but if we deeply find...

View Article

By: Robb Reck

Jeff, I completely agree that formula is flawed. I have always believed more in the very basic Risk = Probability * Impact. The vulnerabilities and threats from the original formula would factor into...

View Article

By: Remington Winters

Jeff, I think your argument is deficient as it does not seem to take into account the fact that the equation is meant to be used within a subjective and qualitative framework such as the OWASP RRM...

View Article


By: alex

remmington, as much as I love owasp, rrm also breaks the fundamental laws of mathematics as we know them by performing math other than addition or subtraction on ordinal scales. In addition to what...

View Article

By: Henry

While that is true, in most cases, using R = TxVxI formula is the only practical way of quantifying something that is inherently difficult to quantify. It’s a management tool to aid decision making. In...

View Article

By: Phil Wilson

Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...

View Article


By: Ryburn Ross

Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...

View Article


By: Tom Olzak

[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...

View Article

By: Clint

hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk

View Article

By: Scott Palmer

Jeff, I stumbled on this posting in support of my argument that the formula that many depend on is complete nonsense! It amazes me how many rely/depend on this formula when they don’t realize the...

View Article

By: Roberto

very interesting discussion. My 2-cent corntibute is: in a number of standards the notion of risk is associated to a combination of impact and likelihood, may change some names but the concepts are...

View Article


By: Sabuz

I want to divided the concept into two individual parts Risks & Impact and to define this things for action plan, it should be formulated with this formula threats + vulnerabilities=Risk ≤ Impact...

View Article

By: Scott

The primary problem with any risk formula is the identification and quantification of likelihood. You have to have direct access to the potential adversary, and some relatively controversial...

View Article


By: Henry

While that is true, in most cases, using R = TxVxI formula is the only practical way of quantifying something that is inherently difficult to quantify. It’s a management tool to aid decision making. In...

View Article

By: Phil Wilson

Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...

View Article


By: Ryburn Ross

Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...

View Article

By: Tom Olzak

[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...

View Article

By: Clint

hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk

View Article
Browsing all 36 articles
Browse latest View live


Latest Images