What “Vulnerability” Means in Risk Analysis from a FAIR Perspective
The article explains that in the FAIR risk-analysis model, vulnerability is not defined as a system weakness but as the probability that a threat event will result in a loss event. It contrasts this with common language and traditional cybersecurity usage, where vulnerability usually means a flaw or weakness. By treating vulnerability as a conditional probability, FAIR enables clear, quantitative risk calculations by combining it with the frequency of threat events. The article argues that this precise definition avoids ambiguity and supports more rigorous risk assessments.
Comments
Post a Comment