<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Introduction to FAIR</title>
	<atom:link href="http://fairwiki.riskmanagementinsight.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://fairwiki.riskmanagementinsight.com</link>
	<description>An Online Home for the Factor Analysis of Information Risk (FAIR) Framework</description>
	<lastBuildDate>Mon, 18 Jun 2007 15:24:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title></title>
		<link>http://fairwiki.riskmanagementinsight.com/?p=1</link>
		<comments>http://fairwiki.riskmanagementinsight.com/?p=1#comments</comments>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<dc:creator><ADMINNICENAME></dc:creator>
				<category><![CDATA[Site Business]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[This website is an online version of the whitepaper:
An Introduction to Factor  Analysis of Information Risk (FAIR)
A framework for understanding, analyzing, and measuring information risk
by Jack A. Jones, CISSP, CISM, CISA
You can always find a formal .pdf version of this content >> here ]]></description>
			<content:encoded><![CDATA[<p>This website is an online version of the whitepaper:</p>
<h1>An Introduction to Factor  Analysis of Information Risk (FAIR)</h1>
<p><em>A framework for understanding, analyzing, and measuring information risk</em></p>
<p><em>by Jack A. Jones, CISSP, CISM, CISA</em></p>
<p><strong>You can always find a formal .pdf version of this content <a href="http://www.riskmanagementinsight.com/media/docs/FAIR_introduction.pdf">>> here <<<</a>.</strong></p>
<p>To get started, select &#8220;Introduction&#8221; from the menu on your right.</p>
<h1 class="text"><font size="5" color="black">What is FAIR?</font></h1>
<p class="text"><font size="-1">Information security practices, to-date, have generally been inadequate in helping organizational leadership effectively manage information risk. The shortcomings are primarily the result of information security being practiced as an art rather than science &#8211; i.e., a heavy reliance on practitioner intuition and experience, industry lore, and &#8220;best practices.&#8221; And although intuition, experience, and best practices all provide value, they don&#8217;t consistently enable management to make effective, well-informed decisions. The absence of a working, logical foundation that determines risk means risk management efforts are highly subject to individual bias, myth, dogma, and misinterpretation of the relatively sparse empirical data that exists. </font></p>
<p class="text"><font size="-1">The result? Organizations spend too little or too much time and money, or spend resources in all the wrong places as they attempt to reduce their risk.</font></p>
<h1><span class="text"><font size="-1">The FAIR Risk Management Framework</font></span></h1>
<p class="text"><font size="-1">Factor Analysis of Information Risk (FAIR) provides a framework for understanding, analyzing, and measuring information risk. The outcomes are more cost-effective information risk management, greater credibility for the information security profession, and a foundation from which to develop a scientific approach to information risk management.</font></p>
<p class="text"><strong>FAIR allows organizations to:</strong></p>
<table width="100%" cellspacing="2" cellpadding="4" border="0" class="bulletlist">
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Speak in one language concerning their risk</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Be able to consistently study and apply risk to any object or asset</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">View organizational risk in total</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Defend or challenge risk determination using an advanced analysis framework</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Understand how time and money will impact their security profile</font></td>
</tr>
</table>
<p class="text"><strong>Specific components of the framework include:</strong></p>
<table width="100%" cellspacing="2" cellpadding="4" border="0" class="bulletlist">
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">A taxonomy for information risk<br />
</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Standard nomenclature for information risk terms</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">A framework for establishing data collection criteria</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">Measurement scales for risk factors</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">A computational engine for calculating risk</font></td>
</tr>
<tr>
<td valign="top" align="center" style="width: 10px"><img width="10" height="18" border="0" src="http://www.riskmanagementinsight.com/media/images/pages/all/bullet.png" /></td>
<td class="bulletlist"><font size="-1">A modeling construct for analyzing complex risk scenarios</font></td>
</tr>
</table>
<p>The comments section of this website is regularly monitored.  We welcome questions about FAIR and how the framework works, if you have any questions about any concepts discussed, please feel free to leave a comment, and a FAIR certified analyst will answer as soon as possible.  Please note that we&#8217;d like the comments section to be only for questions &#8211; any other feedback can be left, but may or may not be answered and may or may not be made available to the public.</p>
<p>Thank you and enjoy the website!</p>
<p><a xhref="http://www.technorati.com/claim/ngy5zvvsa" rel="me">Technorati Profile</a></p>
]]></content:encoded>
			<wfw:commentRss>http://fairwiki.riskmanagementinsight.com/?feed=rss2&amp;p=1</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>
