Risk methodologies — from FAIR to the military RMF

QROS does not invent its own risk language. It maps every cryptographic and quantum finding to the methodologies regulators and defense bodies already use — FAIR for economic impact, NIST CSF 2.0 and ISO 27005 for treatment, OCTAVE and ENISA for threat scenarios, CVSS for vulnerability severity and the NIST SP 800-37 RMF for authorization — so the same evidence serves a bank's DORA audit and a defense system's ATO.

Quantify
FAIR

Loss frequency × loss magnitude → ALE in €/year, per scenario, in the guided assessment.

Map controls
NIST CSF 2.0

Identify / Protect / Detect / Respond / Recover — every CIS control maps to a CSF subcategory.

Treat
ISO 27005

Risk treatment options (modify / retain / avoid / share) with residual risk after remediation.

Scenarios
OCTAVE

Asset × threat × vulnerability triples drive the department’s risk scenarios.

Threats
ENISA

EU threat-landscape categories tag each finding (supply chain, crypto agility, quantum).

Severity
CVSS

Every CVE inherits its NVD base score and vector, filtered by vuln:critical / high / medium.

Authorize
NIST SP 800-37 RMF

Categorize → select → implement → assess → authorize → monitor, for defense ATO.

Hardenening
CIS / STIG / PCI

Benchmark controls become the implementation step of the RMF, scored per host.

How QROS applies each

The guided assessment feeds one model: departments define their assets (OCTAVE), each asset gets a cryptographic posture scan (CVSS-tagged CVEs + weak-key detection), the posture is monetized as an annual loss expectancy (FAIR), the result is mapped to NIST CSF and ISO 27005 treatment, and the CIS/STIG/PCI hardening playbooks become the RMF implementation step. One evidence base, every framework.

Run a guided assessment →

FAQ

Which risk methodologies does QROS support?

FAIR, NIST CSF 2.0, ISO 27005, OCTAVE, ENISA, CVSS and the NIST SP 800-37 Risk Management Framework. QROS maps every finding to all of them so the same evidence serves a DORA, ISO 27001 or defense ATO audit.

Is FAIR the default for economic impact?

Yes. FAIR (loss frequency × loss magnitude) produces the annual loss expectancy in €/year shown in the crisis-cabinet scenarios, with CVSS providing the technical severity and NIST CSF the control gaps.

Try this service with QROS

Explore now →