An organization is using the FAIR (Factor Analysis of Information Risk) model in their Azure risk assessment. FAIR primarily focuses on quantifying risk in terms of:
-
A
Compliance gaps against regulatory frameworks
-
B
Probable frequency and probable magnitude of loss in financial terms
-
C
Control maturity scores across NIST domains
-
D
Threat actor profiles and attack vectors