CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

An organization is using the Factor Analysis of Information Risk (FAIR) methodology to quantify the risk of a cyber-attack leading to a data breach. The risk team is currently estimating the frequency with which a threat agent (e.g., a hacker group) is likely to initiate an attack against the organization's assets. Which FAIR component is the team primarily focused on determining at this stage?

  1. AVulnerability Factor (VF)
  2. BLoss Event Frequency (LEF)
  3. CThreat Event Frequency (TEF)
  4. DPrimary Loss (PL)
Show answer & explanation

Correct answer: C. Threat Event Frequency (TEF)

In FAIR, Threat Event Frequency (TEF) specifically refers to the probable frequency, within a given timeframe, that a threat agent will act against an asset. This aligns directly with estimating how often a hacker group initiates an attack.

Why the other options are wrong

  • A. Vulnerability Factor (VF) is a sub-component of 'Probability of Action' or 'Resistance Strength', not the frequency of the threat agent initiating an action.
  • B. Loss Event Frequency (LEF) is the probable frequency that a loss will materialize, considering both TEF and the probability of a successful attack.
  • D. Primary Loss (PL) is a component of 'Loss Magnitude', referring to the direct financial impact of a loss event, not its frequency.

FAIR Components

A quantitative risk analysis model that defines, measures, and analyzes information risk.

  • Focuses on Loss Event Frequency and Loss Magnitude.
  • Breaks down risk into measurable factors.
  • Provides a common language for risk quantification.

Memory trick: FAIR: Frequency And Impact Really (matter).

More IT Risk Assessment questions