Skip to content
Capability/Functional Capabilities

Risk Management

ROAM integration for enterprise risk orchestration

01 / Overview
<10%
of randomly selected hazard pairs a typical risk matrix compares unambiguously

Louis Anthony (Tony) Cox, Jr., "What's Wrong with Risk Matrices?", Risk Analysis 28(2), April 2008, pp. 497-512: typical risk matrices "can correctly and unambiguously compare only a small fraction (e.g., less than 10%) of randomly selected pairs of hazards".

Risk management capabilities provide enterprise visibility into security and compliance risks with prioritized remediation guidance. Integrated with ROAM, Thalorin orchestrates risk across the organization with quantitative analysis, treatment tracking, and executive reporting.

The reference text moved. NIST withdrew IR 8286, Integrating Cybersecurity and Enterprise Risk Management, on 18 December 2025 and replaced it with Revision 1 published that month; the companion volumes were reissued as 8286A-r1, 8286B-upd1, 8286C-r1 and 8286D-upd1. What survived the revision is the machinery — the cybersecurity risk register and the risk detail record, both published with JSON and spreadsheet schemas. The series exists because a register is only useful if it aggregates, and aggregation needs an agreed shape before a tool.

The three frameworks most often claimed together answer different questions and do not substitute for one another. ISO 31000:2018 is published as guidelines, states no auditable requirements, and has no accredited certification scheme behind it. The NIST Risk Management Framework in SP 800-37 Rev 2 is a seven-step process — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — ending in one official's documented acceptance of risk for one system boundary. Open FAIR, whose Body of Knowledge The Open Group issued at Version 2.0 in 2025, is a measurement model that puts calibrated ranges on the probable frequency and monetised cost of future loss.

What sinks most programmes is arithmetic performed on labels. A five-by-five matrix multiplies an ordinal likelihood by an ordinal impact and produces a figure treated as cardinal for the rest of its life. Cox's 2008 analysis in Risk Analysis found that typical risk matrices can correctly and unambiguously compare only a small fraction — his figure is less than ten per cent — of randomly selected pairs of hazards, and can mistakenly assign a higher qualitative rating to a quantitatively smaller risk. CSF 2.0 asks at GV.RM-06 for "a standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks". A colour is not a method.

Every risk here carries the method that produced it. A quantified estimate keeps its distribution and its stated assumptions; a qualitative one keeps the scale it was scored on, so the two are never silently combined. Treatments bind to the controls that implement them, which means a control that stops operating reopens the risk it was closing instead of leaving behind a residual score nobody recomputed — and system-level registers roll into the enterprise risk profile SP 800-221 describes without being re-scored at each tier.

02 / Challenges

Compliance operations need modern infrastructure

Ordinal scores treated as arithmetic

Likelihood and impact expressed as ranks cannot be multiplied into a meaningful product, yet the product is what reaches the prioritisation queue. The resulting order can invert the underlying quantitative risk without anyone in the chain noticing.

Residual risk recomputed on a calendar

SP 800-53 RA-3 requires the risk assessment be updated when there are significant changes to the system or its environment of operation. Most registers refresh annually, so a residual score outlives the control that justified it.

System authorisations do not aggregate

The RMF Authorize step yields one official's acceptance of risk for one boundary. SP 800-221 asks for a portfolio view across boundaries, and stacking authorisation letters produces a pile rather than a profile.

The annual written report to the board

Under the FTC Safeguards Rule at 16 CFR 314.4(i), the Qualified Individual must report in writing at least annually to the board. A deck assembled by hand each cycle cannot be reconciled to the register it summarises.

03 / Capabilities

How Thalorin helps

NIST RMFISO 31000FAIR

Enterprise risk visibility

Registers held at system and mission level roll into the enterprise risk profile SP 800-221 describes, so moving between tiers is a change of view rather than a fresh scoring exercise.

Risk quantification

Quantified risk is expressed in Open FAIR terms — calibrated ranges for threat event frequency and loss event frequency rather than a point estimate — with the distribution and its assumptions carried alongside.

Treatment tracking

A treatment binds to the controls that implement it, so a control that degrades reopens the risk it was closing rather than leaving a residual figure with nothing behind it.

Risk register management

The register holds risk detail records in the shape IR 8286 Rev 1 publishes schemas for, so an entry carries its owner, its response decision and its history instead of a spreadsheet row.

Executive dashboards

Executive views derive from the register itself, which is what lets the written annual report required at 16 CFR 314.4(i) reconcile line by line to the records that produced it.

Risk-based prioritization

Prioritisation runs against the risk appetite and tolerance statements CSF 2.0 requires at GV.RM-02, using one declared method rather than a scale that shifts between business units.

Questions

Risk Management: common questions

Can an organisation be certified to ISO 31000?

No. ISO 31000:2018 is published as guidelines — principles, a framework and a process — and it states no auditable requirements, so there is nothing for a certification body to audit against and no accredited scheme behind it. Individuals can hold credentials demonstrating knowledge of it; organisations cannot be certified to it. The standard that does carry organisational certification here is ISO/IEC 27001, which certifies a management system. Anyone offering your organisation an ISO 31000 certificate is describing something that does not exist — which matters when a customer contract asks for one.

What is the difference between NIST RMF and an enterprise risk programme?

Scope and output. The RMF, defined in SP 800-37 Rev 2, applies seven steps to a system — prepare, categorize, select, implement, assess, authorize, monitor — and ends when an authorising official accepts the residual risk for that boundary. An enterprise programme asks a different question: what the aggregate exposure is across boundaries, expressed so an executive committee can weigh it against risks that are not technological. SP 800-221 and IR 8286 Rev 1 address the roll-up the RMF deliberately does not.

Is FAIR worth adopting if we already have a risk matrix?

It depends on what the matrix is being asked to carry. If it only sorts a backlog for one security team, ordinal scoring is defensible. If its output is being multiplied, compared across business units, or converted into a budget request, it is being used past what it can support — Cox's 2008 study found typical matrices can correctly and unambiguously compare only a small fraction, less than ten per cent, of randomly selected pairs of hazards. Open FAIR's value is that the frequency and the cost of a loss event are quantities you can put a defensible range around.

Did NIST update its guidance on cybersecurity and enterprise risk management?

Yes. IR 8286 was withdrawn on 18 December 2025 and superseded by IR 8286 Revision 1, published that December, with its four companion volumes reissued alongside it. The revision keeps the cybersecurity risk register and the risk detail record as its central artifacts and publishes schemas for both in JSON and spreadsheet form. A programme built on the 2020 text should re-read the revision rather than assume continuity.

How do you turn system-level risks into a number a board can use?

Not by averaging scores. The workable route is the one SP 800-221 sets out: system and mission-level registers feed an enterprise risk profile, with every entry carrying the method that produced it so quantified and qualitative items are never combined arithmetically. What a board can act on is exposure in monetary terms against a stated appetite, which is why quantification usually enters a programme at the point board reporting starts.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Risk Management.

See how one evidence artifact satisfies Risk Management requirements alongside every other framework you carry.