Risk Management
DETAIL

Open FAIR – The Open Group Risk Taxonomy (O-RT) Version 3.1 and Risk Analysis (O-RA) Version 2.1 Standards

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

Open FAIR is The Open Group's standard for quantitative information risk analysis, built on Factor Analysis of Information Risk (FAIR). It consists of two companion technical standards: the Risk Taxonomy Standard (O-RT), which provides a standard definition and taxonomy for information security risk and information on how to use it, and the Risk Analysis Standard (O-RA), which describes the process necessary for risk analysts to perform effective information security risk analysis. Together they let practitioners express risk in consistent, economic terms and quantify risk within other security standards and frameworks.

The Open Group Security Forum publishes and maintains the standards. The current editions, O-RT Version 3.1 (document C251) and O-RA Version 2.1 (document C250), were published on May 22, 2025 and supersede Version 3.0.1 and Version 2.0.1 of November 2021. The standards are voluntary and vendor-neutral, and The Open Group runs the Open FAIR Certification for People program for risk analysts, supported by the O-RA Process Guide, the O-RT Example Guide, the Mathematics for Open FAIR Guide, a NIST Cybersecurity Framework cookbook, and a risk analysis tool.

Organizations implement Open FAIR by defining the taxonomy's factors for each risk scenario, the asset, threat, loss event frequency, and loss magnitude, and then following the O-RA process to scope the analysis, gather data through calibrated estimation, model the factors as ranges, and produce a distribution of probable loss that decision makers can compare against risk appetite and the cost of controls. The method is commonly used to prioritize cyber risk investments and to translate qualitative assessments under frameworks such as NIST SP 800-30 and ISO 31000 into financial terms.

Why it Matters

Most risk registers rate risks as high, medium, or low, which cannot tell a board how much loss exposure it carries or whether a control is worth its cost. Open FAIR gives risk analysis a standard taxonomy and a defined process so that risk can be quantified in economic terms, compared across scenarios, and defended when challenged.

Key benefits include:

  • A shared definition of risk

The taxonomy fixes what risk, loss event frequency, loss magnitude, threat, vulnerability, and related terms mean, so analyses from different teams can be compared.

  • Quantified, decision-ready results

Analyses produce ranges of probable loss in financial terms rather than ordinal scores, supporting decisions on controls, insurance, and risk appetite.

  • A repeatable process

O-RA defines the steps an analyst follows, from scoping and data collection to modeling and results, so analyses are consistent and reviewable.

  • Works with existing frameworks

Open FAIR is designed to quantify risk within other standards and frameworks, including the NIST Cybersecurity Framework, for which The Open Group publishes a cookbook.

  • Recognized certification

The Open FAIR Certification for People program validates analysts' knowledge of the taxonomy and analysis standards.

How it Works

The Risk Taxonomy Standard decomposes risk into factors. Risk is expressed as the probable frequency and probable magnitude of future loss: loss event frequency is derived from threat event frequency and vulnerability, which in turn derive from contact frequency, probability of action, threat capability, and resistance strength, while loss magnitude combines primary loss and secondary risk. The taxonomy also defines the forms of loss and the terms the analysis uses, so that every factor an analyst estimates has one meaning.

The Risk Analysis Standard sets out the process. The analyst scopes the scenario by identifying the asset at risk, the threat community, and the loss event, gathers data for each factor using calibrated estimation and available evidence, models each factor as a range with a most-likely value, and combines the factors to produce a distribution of loss exposure. Results are reported with their assumptions and confidence so that decision makers can compare scenarios, evaluate control options, and track exposure over time. The O-RA Process Guide and the Mathematics for Open FAIR Guide give worked detail on estimation and calculation.

Within SmartSuite, risk teams run Open FAIR analyses as structured records: each scenario captures its asset, threat community, and loss event, the taxonomy factors are stored as ranges with their sources and estimators, results are held with assumptions and dates, and scenarios link to the controls, systems, and risk register entries they inform, so quantified exposure is reported alongside the qualitative assessments made under NIST SP 800-30 or ISO 31000.

Key Elements

  • Risk definition

Risk is the probable frequency and probable magnitude of future loss, decomposed into factors that can be estimated and combined.

  • Loss event frequency

Derived from threat event frequency and vulnerability, which the taxonomy further decomposes into contact frequency, probability of action, threat capability, and resistance strength.

  • Loss magnitude

Combines primary loss to the organization with secondary risk arising from the reactions of stakeholders such as customers, regulators, and partners.

  • Risk analysis process

O-RA's scoping, data gathering, modeling, and reporting steps give analyses a consistent structure.

  • Calibrated estimation and ranges

Factors are estimated as ranges with confidence rather than single points, and combined to produce a distribution of loss exposure.

  • Companion guides and tools

The O-RA Process Guide, O-RT Example Guide, Mathematics for Open FAIR Guide, NIST CSF cookbook, and risk analysis tool support application.

  • Certification for people

The Open FAIR Certification for People program validates analysts against the two standards.

Framework Scope

Open FAIR applies to any organization that wants to analyze information security and operational risk quantitatively, in any sector or region. The taxonomy and analysis standards address the definition and analysis of risk; they do not prescribe controls, which come from frameworks such as ISO/IEC 27001, NIST SP 800-53, and CIS Controls, and they do not replace the organization-wide risk management framework described by ISO 31000 or NIST SP 800-39. They are used by risk analysts, security leaders, and internal audit to prioritize and justify risk treatment decisions.

Framework Objectives

The standards exist so that information risk can be defined, analyzed, and communicated consistently in economic terms.

Provide a standard definition and taxonomy for information security risk.

Describe the process risk analysts follow to perform effective information security risk analysis.

Enable risk to be expressed as probable frequency and magnitude of loss rather than ordinal ratings.

Allow practitioners to quantify risk within other security standards and frameworks.

Support consistent, reviewable analyses through calibrated estimation and documented assumptions.

Underpin a certification program that validates analysts' competence.

Framework in Context

Open FAIR is the quantitative complement to the risk assessment processes in NIST SP 800-30 Rev. 1, ISO/IEC 27005, and ISO 31000 and the risk assessment techniques of ISO 31010; it supplies the taxonomy and analysis method those documents leave open. The Open Group publishes a cookbook for applying Open FAIR to the NIST Cybersecurity Framework, and the method is used to prioritize controls drawn from ISO/IEC 27001, NIST SP 800-53, and CIS Controls and to inform enterprise risk management under COSO ERM 2017. The FAIR Institute promotes the underlying FAIR model, while The Open Group holds the standards.

Common Framework Mappings

Open FAIR is commonly mapped to the risk management and assessment standards it quantifies and to the control frameworks whose priorities it informs.

Mapped frameworks include:

NIST SP 800-30 Rev. 1

ISO 27005:2022

ISO 31000:2018

ISO 31010:2009

NIST CSF 2.0

NIST SP 800-39

COSO ERM 2017

ISO 27001:2022

NIST 800-53 Rev.5

CIS Controls v8.1

At a Glance
Open FAIR – The Open Group Risk Taxonomy (O-RT) Version 3.1 and Risk Analysis (O-RA) Version 2.1 Standards
  • Classification
    Category
    Risk Management
    Domain
    Risk Management
    Framework Family
    Other
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    The Open Group
  • Versioning
    Version
    O-RT Version 3.1 (C251) and O-RA Version 2.1 (C250)
    Effective Date
    May 22, 2025
    Issue Date
    May 22, 2025
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: No

The O-RT and O-RA standards are published by The Open Group under its licence terms and are downloaded from its publications site with registration; their text is not included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
Open FAIR at The Open Group
The Open Group's Open FAIR page describing the taxonomy and analysis standards, certification, and supporting guides.
Risk Taxonomy (O-RT), Version 3.1 (C251)
The publications entry for the current Risk Taxonomy Standard, published May 22, 2025, superseding Version 3.0.1.
Risk Analysis (O-RA), Version 2.1 (C250)
The publications entry for the current Risk Analysis Standard, published May 22, 2025, superseding Version 2.0.1.
Open FAIR Certification for People
The Open Group's certification program for risk analysts based on the O-RT and O-RA standards.
SMARTSUITE

How SmartSuite Supports Open FAIR

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For Open FAIR, SmartSuite stores each scenario's taxonomy factors as ranges with their sources, holds the resulting loss exposure with its assumptions, and links scenarios to the controls and risk register entries they inform.

Risk Scenario Library

Hold assets, threat communities, loss events, and the O-RT factor estimates for every scenario in one structured record set.

Ownership, Cadence, and Accountability

Assign scenario owners and analysts, schedule re-analysis, and route results to risk committees through approval workflows.

Evidence Collection and Audit Trail

Attach data sources, calibration notes, and expert estimates to each factor with timestamps and reviewers.

Analysis and Exposure Tracking

Record loss exposure distributions and most-likely values, compare scenarios, and track exposure over time.

Risk and Control Alignment

Link scenarios to ISO/IEC 27001, NIST SP 800-53, and CIS controls and to the qualitative risk register so quantified and qualitative views stay consistent.

Executive Risk Reporting

Report loss exposure, control return on investment, and risk appetite comparisons to executives and the board.

Related frameworks

NIST SP 800-30 Rev. 1

NIST SP 800-30 Rev. 1 is the NIST guide for conducting information security risk assessments: how to prepare, conduct, communicate, and maintain them at every tier of the organization.

ISO 27005:2022

ISO/IEC 27005:2022 provides guidance on identifying, analyzing, evaluating, and treating information security risks in support of an ISO/IEC 27001 ISMS.

ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO 31010:2009

ISO 31010:2009 provides guidance on selecting and applying risk assessment techniques to identify, evaluate, and manage organizational risks.

NIST SP 800-39

NIST SP 800-39 guides organizations to identify, assess, and manage information security risk at all enterprise levels.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ONBOARDING FAQS

Frequently Asked Questions For Open FAIR

What is Open FAIR?

Open FAIR is The Open Group's standard for quantitative information risk analysis, based on Factor Analysis of Information Risk. It consists of the Risk Taxonomy Standard (O-RT), which defines risk and its factors, and the Risk Analysis Standard (O-RA), which describes the process analysts follow.

What are the current versions?

O-RT Version 3.1 (document C251) and O-RA Version 2.1 (document C250), both published by The Open Group on May 22, 2025. They supersede O-RT Version 3.0.1 and O-RA Version 2.0.1 of November 2021.

How does Open FAIR define risk?

Risk is the probable frequency and probable magnitude of future loss. Loss event frequency derives from threat event frequency and vulnerability, and loss magnitude combines primary loss with secondary risk, so each factor can be estimated and combined.

How does Open FAIR relate to NIST SP 800-30 and ISO 31000?

Those documents describe risk assessment processes but leave the analysis method open. Open FAIR supplies a taxonomy and quantitative method that fits inside them, and The Open Group publishes a cookbook for applying it to the NIST Cybersecurity Framework.

Is there an Open FAIR certification?

Yes. The Open FAIR Certification for People program, run by The Open Group, validates risk analysts' knowledge of the O-RT and O-RA standards.

Who publishes Open FAIR and is it free?

The Open Group Security Forum publishes and maintains the standards. They are downloaded from The Open Group's publications site under its licence terms, and supporting guides and a risk analysis tool are also available there.

How does SmartSuite support Open FAIR?

SmartSuite stores each scenario's factor estimates as ranges with their sources, holds loss exposure results with assumptions and dates, links scenarios to controls and the risk register, and reports exposure and control value to executives.

Operationalize Open FAIR with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.