1. Estimate event probability
Enter the chance of at least one material identity-related incident during a year.
2. Enter incident impact
Use the expected total cost of response, downtime, recovery, legal work, and business disruption for one event.
3. Rate existing controls
Estimate how much current authentication, authorization, monitoring, and lifecycle controls reduce the modeled risk.
4. Set the identity exposure factor
Use this factor to represent how much of the incident impact is attributable to identity and access weaknesses.
5. Review residual exposure
Compare the remaining annual exposure with the gross exposure and estimated control-driven reduction.