Lab 19: Security Metrics & Risk Quantification
Objectives
Step 1: FAIR Risk Model
Risk
├── Loss Event Frequency (LEF)
│ ├── Threat Event Frequency (TEF) — how often does the threat act?
│ └── Vulnerability (VULN) — likelihood threat succeeds if it acts
│ ├── Threat Capability (TCAP) — threat actor's skill level
│ └── Resistance Strength (RS) — strength of your controls
│
└── Loss Magnitude (LM)
├── Primary Loss — direct costs (response, recovery, notification)
│ ├── Response costs
│ ├── Replacement costs
│ └── Competitive advantage loss
└── Secondary Loss — indirect costs (fines, litigation, reputation)
├── Regulatory fines
├── Lawsuit settlements
└── Customer churn revenueStep 2: FAIR Monte Carlo Simulation
Step 3: FAIR — Multiple Scenario Comparison
Scenario
ALE (P50)
Control Cost
Risk Reduction
ROI
Step 4: Security KPIs
KPI
Formula
Target
Measurement Cadence
KPI
Description
Step 5: Security ROI Models
Step 6: Communicating Risk to the Board
Step 7: Security Budget Benchmarking
Industry
Security/IT Budget %
Security/Revenue %
Step 8: Capstone — Risk Quantification for CISO Report
Summary
Concept
Key Points
PreviousLab 18: Network Security Architecture ReviewNextLab 20: Capstone — Enterprise Security Architecture
Last updated
