FAIR

Also known as: Factor Analysis of Information Risk

framework · cybersecurity · regulatory-standard

Quantitative risk framework decomposing risk into loss event frequency and loss magnitude with probabilistic factors.

FAIR (Factor Analysis of Information Risk) is the quantitative information-risk methodology developed by Jack Jones beginning in the early 2000s while at Nationwide Insurance, with substantial subsequent development through Jones's RiskLens consultancy and standardization as Open FAIR through The Open Group. The framework's central commitment is that information risk can and should be quantified in monetary terms (annualized loss expectancy, value-at-risk distributions) rather than expressed in qualitative high/medium/low ratings that obscure decision-making. FAIR decomposes risk into Loss Event Frequency (how often loss events occur) and Loss Magnitude (how much loss results), each further decomposed: LEF = Threat Event Frequency × Vulnerability; LM = Primary Loss + Secondary Loss (with secondary loss decomposed into productivity, response, replacement, fines/judgments, competitive advantage, reputation). Each factor is estimated as a probability distribution (typically using PERT distributions over min/most-likely/max estimates), with Monte Carlo simulation aggregating to produce loss-distribution outputs. FAIR explicitly distinguishes itself from qualitative approaches (NIST 800-30 high/medium/low matrices, ISO 27005 qualitative) and from purely actuarial approaches that require historical loss data many organizations don't have. The framework has been substantially adopted in enterprise risk management, particularly in financial services, with growing recognition by regulators and standards bodies. Open FAIR (The Open Group standard) provides the canonical reference and a certification track.

Originators

Jack A. Jones (foundational at Nationwide Insurance, early 2000s); subsequent development through RiskLens and The Open Group's Open FAIR standard; co-author Jack Freund (Measuring and Managing Information Risk, 2014) high

Year / Decade

Early 2000s development; 2009 (Open FAIR Standard); 2014 (Jones-Freund book); ongoing high

Primary sources

Jones, J.A. (2005). 'An Introduction to Factor Analysis of Information Risk' (FAIR white paper), Freund, J. & Jones, J.A. (2014). Measuring and Managing Information Risk: A FAIR Approach, The Open Group (2009, multiple editions). Open FAIR Risk Analysis Standard high

Band notes

Quantitative methodology now standardized as Open FAIR through The Open Group; distinct from qualitative risk-rating approaches.

Core components

Primary use case

Quantitative cyber-risk analysis particularly in financial services; foundation for risk-based budget allocation and security investment decisions; basis for board-level cyber-risk reporting in monetary terms; integration with enterprise risk management; growing use in regulatory contexts (NYDFS Part 500 risk assessments, OCC guidance); foundation for substantial commercial software (RiskLens, others); pedagogical reference in cyber-risk-quantification education.

Common criticisms

Lineage

Siblings
NIST Risk Management Framework