1. Estimate annual probability
Define the chance that the selected security scenario occurs within one year.
2. Enter financial impact
Use the expected cost of one event under current business conditions.
3. Measure architecture coverage
Estimate the percentage of relevant users, devices, workloads, and data paths included.
4. Rate control strength and maturity
Separate technical capability from the consistency of deployment, operation, monitoring, and response.
5. Review residual risk
Use the effective control reduction and avoided exposure to identify which assumption most limits the outcome.