| Decision Support Metrics
Most information risk tools available today focus on vulnerabilities and their known exploits. This focus on the 'known space' accomplishes little to illuminate risk and nothing at all to increase understanding of the organization's capability to withstand the possible attack vectors from the 'unknown space.' By contrast, Prevari's Technology Risk Manager (TRM) presents a consistent measure of the inherent structural integrity of the organization's computing environment. This allows organizations to proactively manage risk in the face of both known and unknown attack vectors. Prevari's Compliance Risk Manager (CRM) directly maps and weights specific compliance objectives to an organization's quantitative information risk profile.
 |
TRM - Risk Indices
- Confidentiality
- Integrity
- Availability
- Audit
|
 |
CRM - Compliance Frameworks
- DIACAP
- NIST 800-53
- ISO-17799/27002
- CobiT
- PCI-DSS
- SOX
- GLBA
- HIPAA
- Safe Harbor
- Custom Policies
|
|