Quantcast
Channel: Comments on: Why the “Risk = Threats x Vulnerabilities x Impact” Formula is Mathematical Nonsense
Browsing index pages (36 articles)

By: waleed afifi

hi, I am a Master of Disaster Recovery Planز How can I measure the risks in cloud computing? pls. give me answer at: gigawaleedafifi@yahoo.com

View Article


By: JoeBlow

Presenting or outlining a problem without a solution is workplace no-no 101. I don’t see you providing a solution except possibly complaining about a flawed mathematical equation. I agree with Henry,...

View Article


By: Scott

The primary problem with any risk formula is the identification and quantification of likelihood. You have to have direct access to the potential adversary, and some relatively controversial...

View Article

By: Sabuz

I want to divided the concept into two individual parts Risks & Impact and to define this things for action plan, it should be formulated with this formula threats + vulnerabilities=Risk ≤ Impact...

View Article

By: Roberto

very interesting discussion. My 2-cent corntibute is: in a number of standards the notion of risk is associated to a combination of impact and likelihood, may change some names but the concepts are...

View Article


By: Scott Palmer

Jeff, I stumbled on this posting in support of my argument that the formula that many depend on is complete nonsense! It amazes me how many rely/depend on this formula when they don’t realize the...

View Article

By: Clint

hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk

View Article

By: Tom Olzak

[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...

View Article


By: Ryburn Ross

Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...

View Article


By: Phil Wilson

Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...

View Article

By: waleed afifi

hi, I am a Master of Disaster Recovery Planز How can I measure the risks in cloud computing? pls. give me answer at: gigawaleedafifi@yahoo.com

View Article

By: JoeBlow

Presenting or outlining a problem without a solution is workplace no-no 101. I don’t see you providing a solution except possibly complaining about a flawed mathematical equation. I agree with Henry,...

View Article

By: Scott

The primary problem with any risk formula is the identification and quantification of likelihood. You have to have direct access to the potential adversary, and some relatively controversial...

View Article


By: Sabuz

I want to divided the concept into two individual parts Risks & Impact and to define this things for action plan, it should be formulated with this formula threats + vulnerabilities=Risk ≤ Impact...

View Article

By: Roberto

very interesting discussion. My 2-cent corntibute is: in a number of standards the notion of risk is associated to a combination of impact and likelihood, may change some names but the concepts are...

View Article


By: Scott Palmer

Jeff, I stumbled on this posting in support of my argument that the formula that many depend on is complete nonsense! It amazes me how many rely/depend on this formula when they don’t realize the...

View Article

By: Clint

hi there, how about this: CR = i x (v+c)L/t i = impact v+c = vulnerability + control effectiveness L = likelihood t = time CR = cyber risk

View Article


By: Tom Olzak

[sigh…] It’s just a teaching model, useful for showing the relationships between the risk elements. Other methods of qualitative analysis are used when actually conducting an assessment, but this...

View Article

By: Ryburn Ross

Henry has it right: It’s a mathematical model for determining risk in indeterminate environments: IE it’s an approach you use if you don’t have concrete data. Lacking # of incidents or financial impact...

View Article

By: Phil Wilson

Here, here, Jeff! We fully agree and this is another case-in-point for our need that many, if not most, risk assessment methods need to be tossed and / or fully re-engineered. Best Rehards to you and...

View Article
Browsing index pages (36 articles)


Latest Images