Risk methodologies — from FAIR to the military RMF
QROS does not invent its own risk language. It maps every cryptographic and quantum finding to the methodologies regulators and defense bodies already use — FAIR for economic impact, NIST CSF 2.0 and ISO 27005 for treatment, OCTAVE and ENISA for threat scenarios, CVSS for vulnerability severity and the NIST SP 800-37 RMF for authorization — so the same evidence serves a bank's DORA audit and a defense system's ATO.
Loss frequency × loss magnitude → ALE in €/year, per scenario, in the guided assessment.
Identify / Protect / Detect / Respond / Recover — every CIS control maps to a CSF subcategory.
Risk treatment options (modify / retain / avoid / share) with residual risk after remediation.
Asset × threat × vulnerability triples drive the department’s risk scenarios.
EU threat-landscape categories tag each finding (supply chain, crypto agility, quantum).
Every CVE inherits its NVD base score and vector, filtered by vuln:critical / high / medium.
Categorize → select → implement → assess → authorize → monitor, for defense ATO.
Benchmark controls become the implementation step of the RMF, scored per host.
How QROS applies each
The guided assessment feeds one model: departments define their assets (OCTAVE), each asset gets a cryptographic posture scan (CVSS-tagged CVEs + weak-key detection), the posture is monetized as an annual loss expectancy (FAIR), the result is mapped to NIST CSF and ISO 27005 treatment, and the CIS/STIG/PCI hardening playbooks become the RMF implementation step. One evidence base, every framework.
Run a guided assessment →FAQ
Which risk methodologies does QROS support?
FAIR, NIST CSF 2.0, ISO 27005, OCTAVE, ENISA, CVSS and the NIST SP 800-37 Risk Management Framework. QROS maps every finding to all of them so the same evidence serves a DORA, ISO 27001 or defense ATO audit.
Is FAIR the default for economic impact?
Yes. FAIR (loss frequency × loss magnitude) produces the annual loss expectancy in €/year shown in the crisis-cabinet scenarios, with CVSS providing the technical severity and NIST CSF the control gaps.
Try this service with QROS
Explore now →