CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium
An organization is using the Factor Analysis of Information Risk (FAIR) methodology to quantify the risk of a cyber-attack leading to a data breach. The risk team is currently estimating the frequency with which a threat agent (e.g., a hacker group) is likely to initiate an attack against the organization's assets. Which FAIR component is the team primarily focused on determining at this stage?
- AVulnerability Factor (VF)
- BLoss Event Frequency (LEF)
- CThreat Event Frequency (TEF)
- DPrimary Loss (PL)
Show answer & explanationAnswer & explanation
Correct answer: C. Threat Event Frequency (TEF)
In FAIR, Threat Event Frequency (TEF) specifically refers to the probable frequency, within a given timeframe, that a threat agent will act against an asset. This aligns directly with estimating how often a hacker group initiates an attack.
Why the other options are wrong
- A. Vulnerability Factor (VF) is a sub-component of 'Probability of Action' or 'Resistance Strength', not the frequency of the threat agent initiating an action.
- B. Loss Event Frequency (LEF) is the probable frequency that a loss will materialize, considering both TEF and the probability of a successful attack.
- D. Primary Loss (PL) is a component of 'Loss Magnitude', referring to the direct financial impact of a loss event, not its frequency.
FAIR Components
A quantitative risk analysis model that defines, measures, and analyzes information risk.
- Focuses on Loss Event Frequency and Loss Magnitude.
- Breaks down risk into measurable factors.
- Provides a common language for risk quantification.
Memory trick: FAIR: Frequency And Impact Really (matter).