-

New ISACA Paper Enables Enterprises to Use Cyberrisk Quantification to Improve Approach to Cybersecurity Risk

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Cyberrisk quantification (CRQ) expresses cybersecurity risk in terms of monetary value to the enterprise, translating technology concerns into business concerns. A new white paper from ISACA, Cyberrisk Quantification, addresses the importance of acquiring useful data and amplifying it as part of a CRQ analysis.

The white paper outlines considerations related to measurement—exploring verbal, ordinal and ratio scales and the issues involved with each—as well as dives into the methods for gathering data, including external sources, internal data sources, and the opinions of subject matter experts.

Cybersecurity practitioners can then learn about how Monte Carlo Simulations can be used to transform quantified inputs into CRQ outputs, as well as how to integrate CRQ with other risk assessment methods, including control-based assessments and vulnerability assessments and static/dynamic code analysis.

“CRQ can be a critical enabler of improving organizations’ approach to cyber risk. However, cybersecurity measurement can bring its own set of challenges, including accurately gathering data and addressing issues with verbal and ordinal scales used to measure the risk,” says Paul Phillips, CISA, CISM, MBA, ISACA IT risk professional practices lead. “By understanding the CRQ techniques and additional risk assessment methods that can be implemented, as well as acquiring the right data from both internal and external sources along with SME insights, enterprises can have a clearer picture of the overarching threat landscape.”

This topic will be addressed in further depth at the upcoming complimentary webinar “Quantifying Cyber Risk,” on 10 June 2021 at 12:00 PM (EDT) / 11:00 AM (CDT) / 9:00 AM (PDT) / 4:00 PM (UTC), presented by Jack Freund, Ph.D., Head of Cyber Risk Methodology at VisibleRisk, and Jack Jones, Chief Risk Scientist, RiskLens and Chairman of the FAIR Institute. To register, visit www.isaca.org/education/online-events/lms_w061021.

For a complimentary copy of Cyberrisk Quantification, visit www.isaca.org/bookstore/bookstore-wht_papers-digital/whpcrq. Additional ISACA cybersecurity resources can be found at www.isaca.org/training-and-events/cybersecurity.

About ISACA

ISACA® (www.isaca.org) is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation.

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

ISACA


Release Versions

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Kristen Kessinger, communications@isaca.org, +1.847.660.5512

More News From ISACA

ISACA Authorized as the CAICO for the US Department of War’s CMMC Program

WASHINGTON--(BUSINESS WIRE)--Global professional association ISACA—best known for its Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) certifications—has been authorized as the new and exclusive CMMC Assessor and Instructor Certification Organization (CAICO) for the Cybersecurity Maturity Model Certification (CMMC) program of the US Department of War (DoW). This means ISACA is the trusted credentialing leader to manage the training, examination, and...

ISACA to Lead Global Credentialing for CMMC Cybersecurity Framework as International Cyber Readiness Standards Rise

BRUSSELS & LONDON & MADRID & BERLIN--(BUSINESS WIRE)--As cyber threats escalate and governments raise expectations around operational resilience, ISACA has been appointed to lead the global credentialing programme for the U.S. DoW’s Cybersecurity Maturity Model Certification (CMMC) program. The appointment positions ISACA – the international association for cybersecurity, audit and digital trust – as the exclusive CMMC Assessor and Instructor Certification Organization (CAICO), responsible for...

ISACA, Nasscom Join Hands to Standardize Digital Skills for India’s Workforce

NEW DELHI--(BUSINESS WIRE)--ISACA, a global professional association and learning organization working in digital trust fields serving 185,000 members and operating in more than 190 countries, has exchanged an MoU with IT-ITeS SSC Nasscom, the national standard-setting body for IT skills for the alignment of its credentials to NSQF (National Skill Qualification Framework). Sector Skills Council Nasscom, set up under the aegis of National Skill Development Corporation (NSDC) and Ministry of Skil...
Back to Newsroom