Tag Archives: independence

Why the “Risk = Threat x Vulnerability x Impact” Formula is Mathematical Nonsense — Part 2

– In my last post, I argued that security risk managers should stop using the “Risk = Threat x Vulnerability x Impact” formula (hereafter, the “R=TVC formula”), for two reasons. First, the variables “Threat” and “Vulnerability” are typically undefined; indeed,…