FAIR
Also known as: Factor Analysis of Information Risk
Quantitative risk framework decomposing risk into loss event frequency and loss magnitude with probabilistic factors.
FAIR (Factor Analysis of Information Risk) is the quantitative information-risk methodology developed by Jack Jones beginning in the early 2000s while at Nationwide Insurance, with substantial subsequent development through Jones's RiskLens consultancy and standardization as Open FAIR through The Open Group. The framework's central commitment is that information risk can and should be quantified in monetary terms (annualized loss expectancy, value-at-risk distributions) rather than expressed in qualitative high/medium/low ratings that obscure decision-making. FAIR decomposes risk into Loss Event Frequency (how often loss events occur) and Loss Magnitude (how much loss results), each further decomposed: LEF = Threat Event Frequency × Vulnerability; LM = Primary Loss + Secondary Loss (with secondary loss decomposed into productivity, response, replacement, fines/judgments, competitive advantage, reputation). Each factor is estimated as a probability distribution (typically using PERT distributions over min/most-likely/max estimates), with Monte Carlo simulation aggregating to produce loss-distribution outputs. FAIR explicitly distinguishes itself from qualitative approaches (NIST 800-30 high/medium/low matrices, ISO 27005 qualitative) and from purely actuarial approaches that require historical loss data many organizations don't have. The framework has been substantially adopted in enterprise risk management, particularly in financial services, with growing recognition by regulators and standards bodies. Open FAIR (The Open Group standard) provides the canonical reference and a certification track.
Core components
- Loss Event Frequency (LEF) = Threat Event Frequency × Vulnerability
- Loss Magnitude (LM) = Primary Loss + Secondary Loss
- Six secondary loss types: productivity, response, replacement, fines/judgments, competitive advantage, reputation
- PERT distributions for factor estimates
- Monte Carlo simulation for aggregation
- Quantification in monetary terms (annualized loss expectancy, VaR)
- Distinction from qualitative high/medium/low approaches
- Open FAIR as canonical standard through The Open Group
- Certification track
Primary use case
Quantitative cyber-risk analysis particularly in financial services; foundation for risk-based budget allocation and security investment decisions; basis for board-level cyber-risk reporting in monetary terms; integration with enterprise risk management; growing use in regulatory contexts (NYDFS Part 500 risk assessments, OCC guidance); foundation for substantial commercial software (RiskLens, others); pedagogical reference in cyber-risk-quantification education.
Common criticisms
- Estimates of probability distributions for threat event frequency and vulnerability often rest on substantial subjective expert judgment that varies across analysts
- commercial FAIR implementations vary in quality of factor decomposition and estimation
- the framework's apparent quantitative rigor can mask substantial subjectivity in input estimates
- integration with cybersecurity-control prioritization (which controls reduce LEF or LM by how much?) is genuinely difficult
- some critics argue that quantitative risk analysis encourages false precision in domains where uncertainty is fundamentally epistemic (Knightian uncertainty)
- FAIR works better in mature security organizations with substantial data and expertise than in early-stage programs
- certification industry has produced compliance-style FAIR adoption with varying analytical fidelity
- tension between FAIR's commitment to monetary quantification and the practical reality that some cyber consequences (catastrophic systemic events, national-security implications) resist credible monetary estimation
- convergence with broader operational risk quantification has been incomplete.
Lineage
- Siblings
- NIST Risk Management Framework