Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Jeff Lowder

The Difference between Quantitative and Qualitative Risk Analysis and Why It Matters (Part 1)

An analogy should make this point clear. Many if not most or all people will use common expressions like, “It is hot today,” or, “It is cold outside,” usually without knowing the exact numerical temperature. But even if they don’t know the exact numerical temperature, they feel comfortable making comparisons between different temperatures (“It sure is a lot warmer outside today than it was yesterday”). Nevertheless, temperature is a numerical value, even when the person using interval labels like “freezing” or “blazing hot” doesn’t know the temperature and may not even know the exact ranges those labels represent! Along the same lines, qualitative RAs are numerical, even if their numerical nature is obscured in practice.

(to be continued in parts 2 and 3)

Popularity: 43%

2 Comments

  1. Jens Sep 4, 2008 at 12:19 pm | Permalink

    When you write like this, you will make the “schooled” security experts’ (those with all the education and none of the experience) head spin around. Throw “vulnerability” into the mix and explain that they are not “risks” and their heads will explode. I look forward to parts 2 and 3.

  2. PM Hut Nov 20, 2008 at 3:34 pm | Permalink

    This is a concise, and well written introduction on the subject of Risk Analysis.

    Looking forward to some articles on Contingency Planning.

2 Trackbacks

  1. [...] Lowder, J. (2008). “The Difference Between Quantitative and Qualitative Risk Analysis and Why it Matters (Part 1).” BlogInfoSec.org (link here). [...]

  2. [...] as a risk analyst or manager, regardless of the kind of risk to be focused on and even if they use so-called “qualitative” methodologies, includes [...]

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*