-
-
BlogInfoSec.com Sponsors
-
BlogInfoSec.com Partners
Tag Archives: expected value
Why the “Risk = Threat x Vulnerability x Impact” Formula is Mathematical Nonsense — Part 2
August 31, 2010 – 6:00 am
–
In my last post, I argued that security risk managers should stop using the “Risk = Threat x Vulnerability x Impact” formula (hereafter, the “R=TVC formula”), for two reasons. First, the variables “Threat” and “Vulnerability” are typically undefined;…
Why the “Risk = Threats x Vulnerabilities x Impact” Formula is Mathematical Nonsense
August 23, 2010 – 6:00 am
–
Every now and then I will find a security practitioner presenting the following formula when discussing information security risk analysis (ISRA).
Risks = Threats x Vulnerabilities x Impact
In some versions of this formula, the word “Consequence” is sometimes substituted for…