CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

A software development company is migrating its code repositories to a new platform. The risk manager is populating the risk register with potential issues. Which of the following risk statements BEST adheres to the FAIR (Factor Analysis of Information Risk) ontology for effective risk analysis?

  1. AHigh risk of data loss.
  2. BMedium likelihood of a security incident and significant impact.
  3. CPotential for reputational damage due to a security breach.
  4. DRisk of an external attacker exploiting a zero-day vulnerability in the new platform, leading to a loss of confidentiality for proprietary source code, with an estimated loss of $500,000.
Show answer & explanation

Correct answer: D. Risk of an external attacker exploiting a zero-day vulnerability in the new platform, leading to a loss of confidentiality for proprietary source code, with an estimated loss of $500,000.

FAIR emphasizes breaking down risk into quantifiable components: threat event, asset, threat agent, vulnerability, and specific forms of loss (e.g., loss of confidentiality, integrity, availability). Option B clearly specifies the threat agent ('external attacker'), the vulnerability ('zero-day vulnerability'), the asset ('proprietary source code'), the type of loss ('loss of confidentiality'), and a quantitative impact ('estimated loss of $500,000'). This level of detail and specificity is characteristic of FAIR.

Why the other options are wrong

  • A. Too vague; lacks specifics on threat, asset, or type of loss.
  • B. Uses qualitative terms ('Medium likelihood', 'significant impact') rather than the quantitative and granular breakdown preferred by FAIR.
  • C. Describes a potential impact ('reputational damage') but lacks the detailed breakdown of the event, threat, and specific asset at risk, as required by FAIR.

FAIR Ontology

A framework for understanding, analyzing, and measuring information risk in financial terms, by breaking down risk into quantifiable factors.

  • Focuses on quantitative risk analysis.
  • Decomposes risk into standard factors (e.g., Loss Event Frequency, Probable Loss Magnitude).
  • Aims to provide objective, defensible risk measurements.

Memory trick: FAIR breaks risk down like a scientist, then puts a price tag on it.

More IT Risk Assessment questions