算定根拠

この数字はなぜ信用できるのか。

結論
  • CISOaaS のリスク金額は、攻撃チェーン上の客観的指標で算出します(主観的な「発生確率」を使いません)。
  • 損失額は単一の予測値ではなく、確率分布として推定します(95% 信頼区間と最悪ケースを併記)。
  • 投資額は情報セキュリティ経済学の最適理論に基づき、過不足が起きない範囲を示します。
このページで分かること
  • ACRA:攻撃チェーン上で客観的にリスクを定量化
  • FAIR:確率分布で 95% 信頼区間と最悪ケースを表現
  • Gordon-Loeb:情報セキュリティ経済学の最適投資理論
How it's measured

Why we can quantify risk.

CISOaaS assessments rest on our own method ACRA and information security economics.
Not 'a feeling' — a framework for numbers you can defend with evidence.

AC

ACRA — Attack Chain Risk Assessment

Attack Chain Risk Assessment

Traditional risk assessment uses 'impact × probability of occurrence,'
but estimating that probability is highly subjective and its basis is opaque.

ACRA is our own method built to solve this.
It breaks the attack — from initial intrusion to actual damage — into 4 phases,
Position on the attack chainEase of attackPresence of compensating controls and derives a baseline risk from them.
Risk is then mitigated in steps according to implementation status.

Each phase is mapped to MITRE ATT&CK framework tactics,
ensuring consistency with international threat taxonomies.

Loss is computed via the international standard FAIR (Factor Analysis of Information Risk) and Monte Carlo simulation, expressed not as a single point estimate but as a probability distribution. Showing 'what's the 95% range, what's the worst-case' makes executive decisions more confident.

Approach Comparison
Traditional
Impact × Probability

Probability estimates are subjective.
Hard to defend with evidence.

ACRA
Chain position × Ease × Compensating
→ Baseline risk → step-down by implementation status

Objective metrics. MITRE ATT&CK-aligned.

See the underlying logic (4-phase attack chain, loss distribution, optimal investment model)

Attack Chain Phases
Entry(Initial intrusion)
ARO×1.5
Phishing
Vuln exploitation
Credential bypass

Initial Access, Execution, Persistence

Detection(Detection)
ARO×1.5
Log monitoring
Alerting
Incident response

Stealth, Defense Impairment, Discovery

Propagation(Propagation)
ARO×1.0
Privilege escalation
Lateral movement
Credential theft

Privilege Escalation, Lateral Movement

Impact(Impact)
ARO×1.0
Data exfiltration
Ransomware
System destruction

Exfiltration, Impact

Mapped to the MITRE ATT&CK Framework

FM

FAIR + Monte Carlo — loss as a probability distribution

Factor Analysis of Information Risk

Annualized Loss Expectancy (ALE) is computed not as a single point estimate but as a probability distribution. Based on the FAIR standard, per-occurrence loss magnitude is modeled with the PERT distribution and frequency with the Poisson distribution. Monte Carlo simulation then runs 10,000 scenarios.

This gives you 'the 95% range (19 years in 20)' and 'what a 1-in-20-year bad year looks like' — precise loss numbers as input to the optimal investment computation (Gordon-Loeb).

95% confidence interval
Worst-case loss (VaR)
Loss exceedance curve

Loss = Frequency × Magnitude

Annual loss=Σ
Poisson(frequency) × PERT(magnitude)
Glossary
FAIR
Factor Analysis of Information Risk. An international framework that decomposes information risk into 'frequency × magnitude' and expresses it as a probability distribution.
Probability distribution
Instead of fixing a single value, this expresses 'how likely each outcome is.' It captures the typical value, the 95% range, and the worst case at once.
PERT distribution
A distribution shaped by three points — minimum, most likely, and maximum. Aligns well with expert estimates and is used to model per-occurrence loss magnitude.
Poisson distribution
A distribution that models 'how many times an event occurs in a given period.' Used here to estimate the yearly frequency of incidents.
Monte Carlo simulation
A method that samples randomly from the distributions above to run 10,000 scenarios, producing the full distribution of annual losses.

Stepwise risk mitigation

Risk levels step down according to implementation status. If other controls in the same phase work as compensating controls, risk is further reduced.

None
Critical
Partial
High
Sufficient
Medium
Full
No risk
Compensating controls

When other safeguards within the same attack phase are sufficiently implemented, the target safeguard's risk is reduced by one further step.

GL

Gordon-Loeb optimal investment model

Based on the Gordon-Loeb (2002) theory from information security economics, we compute the optimal upper bound for security investment — preventing both over-investment and under-investment.

Optimal Investment Formula

IALE/e
I = investmentALE = annual losse = 2.718...
Under-invested
Optimal range
Over-invested

数字の根拠を、自社の数字で確かめる。

アセスメントの数字は、この算定根拠の上に組み立てられます。実際の数値を一緒に確認したい方はお問い合わせください。

お問い合わせ