Методология — Mimir CRQ
Peraspera Consulting Peraspera
Consulting

Как устроена методология

От входов к распределению потерь

Выберите узел, чтобы увидеть, что он делает и куда передаёт данные, или запустите анимацию, чтобы посмотреть путь целиком — от входов слева и справа до итогового риска наверху.

Итоговый риск Фактор вероятности Фактор ущерба Движок оценки Входные данные
С чего начать
Модель оценки
Итоговый риск — произведение вероятности и ущерба. Модель делит расчёт на две ветви, обрабатывает каждую отдельным движком, затем прогоняет параметры через 10 000+ итераций Монте-Карло — на выходе не одно число, а распределение потерь с доверительным интервалом.
← Выберите любой узел на схеме, чтобы посмотреть детали.
Подсказка: три тёмных узла — движки оценки. Всё остальное либо питает их данными, либо является результатом их работы.

Глоссарий

Показано 64 из 64
Метрики риска
ALE
Annual Loss Exposure — ожидаемые годовые потери. В ядре всегда результат свёртки распределений, не точечное произведение SLE × ARO.
ARO
Annual Rate of Occurrence — частота события в год, производная от P(успех атаки) и Likelihood of Initiation.
SLE
Single Loss Expectancy — величина потерь от одного события, случайная величина, откалиброванная по 10 модулям FAIR-MAM.
CVaR₉₅
Conditional Value at Risk — средние потери в худших 5% исходов. Primary risk-метрика Mimir CRQ вместо VaR — распределения потерь имеют тяжёлые хвосты.
LEC
Loss Exceedance Curve — кривая вероятности превышения заданной суммы потерь за год; основной визуальный вывод Фазы 5.
Value at Risk (VaR)
Максимальный ожидаемый убыток за период с заданной доверительной вероятностью (например, потери, которые не превышаются в 95% случаев). Mimir CRQ использует CVaR₉₅ вместо VaR — распределения потерь имеют тяжёлые хвосты, и VaR не учитывает, насколько плохи исходы за выбранным порогом.
Метрики бюджета
ROSI
(ΔALE − Cost) / Cost — доходность инвестиции в контроль.
ENBIS
ΔALE − Cost — абсолютная чистая выгода инициативы (в отличие от ROSI, не отношение, а разница).
Gordon-Loeb ceiling
z* ≤ (1/e) × ALE ≈ 0.37 × ALE — sanity-check потолок бюджета на защиту актива per-scenario. Превышение — сигнал пересмотреть архитектуру или передать риск страхованию.
Модель зрелости
Coverage / Automation / Governance
Три оси оценки контроля (0–5 каждая, 0–15 итог): доля охваченных активов, независимость от ручных операций, формализация и наличие владельца.
HMM
Hidden Markov Model — модель продвижения атакующего по тактикам ATT&CK; матрица переходов модифицируется зрелостью Protect-контролей, матрица эмиссий — зрелостью Detect-функций.
Фреймворки
FAIR / FAIR-MAM
Factor Analysis of Information Risk — количественная методология риска. FAIR-MAM (2023) добавляет таксономию величины потерь: 10 модулей, 49 параметров.
NIST CSF 2.0 / 800-53
CSF структурирует контроли по функциям (Identify/Protect/Detect/Respond/Recover); 800-53 rev5 — детальный каталог контролей, источник для модели зрелости.
MITRE ATT&CK
База знаний тактик и техник атакующих; маппится на NIST 800-53 через CTID (5 314 связей типа «mitigates»).
Core Risk Concepts
Risk
The quantified outcome of a scenario, calculated as Likelihood times Impact. Expressed as a monetary range with a confidence interval.
Likelihood
The probability that a threat successfully exploits a weakness, given the environment's architecture and existing controls. Assessed via Threat Frequency and Cyber Risk Exposure.
Impact
The extent of damage a risk event can cause. Categorized into Event Loss (immediate) and Post Event Loss (long term).
Risk Scenario
A structured, plausible narrative describing how a threat actor could exploit an exposure to impact assets, operations, or reputation.
Inherent Risk
The level of risk that exists before any controls or mitigations are applied, reflecting exposure in its raw, unmanaged state.
Residual Risk
The level of risk that remains after controls and mitigations have been applied, representing the exposure actually carried by the organization.
Risk Appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives, used as the benchmark against which residual risk is compared.
Risk Tolerance
The acceptable variation around an organization's risk appetite before corrective action is triggered. Where risk appetite sets the target level of risk, risk tolerance sets the boundaries around it.
Risk Transfer
Shifting the financial consequences of a risk to a third party, typically through cyber insurance, rather than reducing its likelihood or impact directly.
Risk Model Parameters
Threat Frequency
How often attacks of a given threat type could occur, modeled with a Poisson distribution and expressed as a three point tuple.
Cyber Risk Exposure
The degree of exposure to a threat for assets in scope, scored as a float between 0 and 1 based on control maturity.
Event Loss
Immediate financial damage from a scenario, such as business interruption, incident response, and incident recovery.
Post Event Loss
Long term consequences after an event, such as regulatory penalties, reputation loss, and customer attrition.
Risk Scenario Structure
Analysis
Defines the scope of what is being analyzed and sets boundaries that specify assets, threat actors, and outcomes, ensuring stakeholders are aligned on what is and isn't being quantified.
Assessment
Enables consistency in how risks are assessed and compared, avoiding ambiguity and permitting repeatability across scenarios.
Modeling
Provides structure for data collection so scenarios are relevant, not generic, and built unique to the organization being assessed.
Decision Making
Assesses and recommends priorities for investments and resource allocation for controls, insurance, and response planning by comparing mitigation costs with anticipated losses.
Risk Scenario Components
Asset at Risk
The specific system, data, process, or resource that could be affected, such as personally identifiable customer information stored in a cloud database.
Threat Actor
An individual or group who could instigate a risk event, such as a cybercriminal, nation state, or insider, whether malicious or non malicious.
Exposures
Weaknesses or flaws in organizational systems, processes, or behavior that could be exploited to cause damage, including weak passwords, unpatched software, or incomplete processes.
Attack Vector
The method or pathway used for an attack, such as a phishing email, malware, social engineering, or physical access.
Event Sequence
The steps or events leading from a threat actor's actions to the impact on the organization.
Business Impact
The potential financial and operational consequences a cyber event could have, such as monetary loss or operational disruption.
CRQ Task Elements
Threat Types
The kind or kinds of threats that occur in a selected risk scenario for analysis, such as ransomware or data exfiltration.
Attack Techniques
The methods actors employ during the attack phases, such as brute force or process injection, typically mapped to a known attack matrix.
Asset Scope
The assets included in a scenario as the targets for assessment, which can be a single asset or a group of devices, accounts, or data.
Security Controls
The control measures that could be used to defend against attack techniques for a given threat type, typically mapped to a recognized control catalog.
Loss Categories
The kinds of losses or costs considered based on the reflected threat type, such as business interruption, investigation cost, or reputational loss, displayed as event or post event parameters.
Statistical Modeling
Three Point Tuple
A representation of the minimum, most likely, and maximum values for a variable, following a Beta PERT distribution to define a realistic range.
Beta PERT Distribution
A statistical distribution used to model the three point tuples, weighting the most likely value while allowing for a realistic spread between the minimum and maximum.
Poisson Distribution
A statistical distribution used to model how often discrete events, such as attacks, occur within a fixed period, used to derive the Threat Frequency tuple.
Monte Carlo Simulation
A computational technique that feeds the model's parameter tuples through tens of thousands of randomized simulation rounds. Rather than producing a single outcome, it generates a full distribution of possible results, letting the simulator quantify variability and express the final quantified risk together with a confidence interval. Results are typically visualized as risk distribution histograms and loss exceedance curves.
Confidence Interval
A statistical range around the quantified result indicating the level of certainty in the simulated outcome.
Frameworks and Systems
NIST SP 800 53
A catalog of security and privacy controls used to classify and map identified exposures into functional control categories.
Control Categories
Six functional groups, Detection, Prevention, Recovery, Mitigation, Support, and Procedure, used to classify controls and model their effect on risk parameters.
Cyber Risk Index
A company wide qualitative risk score, expressed as a floating point number between 0 and 100, distilled from individual asset risk scores.
Peer Reference
Anonymized detection or loss data from organizations with a similar industry, size, location, and revenue profile, used to benchmark a customer's own results.
CREM
Cyber Risk Exposure Management, the broader discipline that tracks exposure and control status across an environment. CREM history and findings feed the Control Assessment and, in turn, the Cyber Risk Exposure parameter.
Control Category Types
Support
Controls that set up the procedure or improve the process when applied to other controls or practices in an organization. Doesn't affect risk parameters directly, but strengthens the other five categories.
Procedure
Controls or practices acknowledged as the initial step to handle a security issue or problem. Like Support, it strengthens the other categories rather than affecting parameters directly.
Detection
Controls that can detect attack attempts and behaviors. Directly lowers Threat Frequency, since visible attacks are more likely to be exposed and fail.
Prevention
Controls that can prevent an attack from being launched successfully. Directly lowers Cyber Risk Exposure.
Recovery
When loss happens, controls that help the organization return to its original state after the event. Directly lowers Event Loss.
Mitigation
When loss happens, controls that mitigate the post loss state. Directly lowers Post Event Loss.
Data Inputs and Systems
Global Attack Intelligence
Extracted results from public intelligence sources, used to evaluate attack parameters with real world context, such as industry wide attack rates.
Self Attack Detection History
A customer's own attack and threat detection history, analyzed to calculate the attack parameter and reflect the organization's specific environment.
Peer Attack Reference
CRQ based detection results from peers with similar profiles, used to inform and benchmark a customer's own attack parameter.
Customer Profile
Anonymized business data on location, industry, size, and revenue, used to create benchmarks for peer comparison.
Event Library
A system that correlates a customer's threat detection and exposure history within the CRQ capability's statistical analysis.
Intelligence Hub
A system that monitors, collects, purifies, and refines data from public intelligence sources.
Ничего не найдено. Попробуйте другой запрос.