Open FAIR – The Open Group Risk Taxonomy (O-RT) Version 3.1 and Risk Analysis (O-RA) Version 2.1 Standards

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
Open FAIR is The Open Group's standard for quantitative information risk analysis, built on Factor Analysis of Information Risk (FAIR). It consists of two companion technical standards: the Risk Taxonomy Standard (O-RT), which provides a standard definition and taxonomy for information security risk and information on how to use it, and the Risk Analysis Standard (O-RA), which describes the process necessary for risk analysts to perform effective information security risk analysis. Together they let practitioners express risk in consistent, economic terms and quantify risk within other security standards and frameworks.
The Open Group Security Forum publishes and maintains the standards. The current editions, O-RT Version 3.1 (document C251) and O-RA Version 2.1 (document C250), were published on May 22, 2025 and supersede Version 3.0.1 and Version 2.0.1 of November 2021. The standards are voluntary and vendor-neutral, and The Open Group runs the Open FAIR Certification for People program for risk analysts, supported by the O-RA Process Guide, the O-RT Example Guide, the Mathematics for Open FAIR Guide, a NIST Cybersecurity Framework cookbook, and a risk analysis tool.
Organizations implement Open FAIR by defining the taxonomy's factors for each risk scenario, the asset, threat, loss event frequency, and loss magnitude, and then following the O-RA process to scope the analysis, gather data through calibrated estimation, model the factors as ranges, and produce a distribution of probable loss that decision makers can compare against risk appetite and the cost of controls. The method is commonly used to prioritize cyber risk investments and to translate qualitative assessments under frameworks such as NIST SP 800-30 and ISO 31000 into financial terms.
Why it Matters
Most risk registers rate risks as high, medium, or low, which cannot tell a board how much loss exposure it carries or whether a control is worth its cost. Open FAIR gives risk analysis a standard taxonomy and a defined process so that risk can be quantified in economic terms, compared across scenarios, and defended when challenged.
Key benefits include:
- A shared definition of risk
The taxonomy fixes what risk, loss event frequency, loss magnitude, threat, vulnerability, and related terms mean, so analyses from different teams can be compared.
- Quantified, decision-ready results
Analyses produce ranges of probable loss in financial terms rather than ordinal scores, supporting decisions on controls, insurance, and risk appetite.
- A repeatable process
O-RA defines the steps an analyst follows, from scoping and data collection to modeling and results, so analyses are consistent and reviewable.
- Works with existing frameworks
Open FAIR is designed to quantify risk within other standards and frameworks, including the NIST Cybersecurity Framework, for which The Open Group publishes a cookbook.
- Recognized certification
The Open FAIR Certification for People program validates analysts' knowledge of the taxonomy and analysis standards.
How it Works
The Risk Taxonomy Standard decomposes risk into factors. Risk is expressed as the probable frequency and probable magnitude of future loss: loss event frequency is derived from threat event frequency and vulnerability, which in turn derive from contact frequency, probability of action, threat capability, and resistance strength, while loss magnitude combines primary loss and secondary risk. The taxonomy also defines the forms of loss and the terms the analysis uses, so that every factor an analyst estimates has one meaning.
The Risk Analysis Standard sets out the process. The analyst scopes the scenario by identifying the asset at risk, the threat community, and the loss event, gathers data for each factor using calibrated estimation and available evidence, models each factor as a range with a most-likely value, and combines the factors to produce a distribution of loss exposure. Results are reported with their assumptions and confidence so that decision makers can compare scenarios, evaluate control options, and track exposure over time. The O-RA Process Guide and the Mathematics for Open FAIR Guide give worked detail on estimation and calculation.
Within SmartSuite, risk teams run Open FAIR analyses as structured records: each scenario captures its asset, threat community, and loss event, the taxonomy factors are stored as ranges with their sources and estimators, results are held with assumptions and dates, and scenarios link to the controls, systems, and risk register entries they inform, so quantified exposure is reported alongside the qualitative assessments made under NIST SP 800-30 or ISO 31000.
Key Elements
- Risk definition
Risk is the probable frequency and probable magnitude of future loss, decomposed into factors that can be estimated and combined.
- Loss event frequency
Derived from threat event frequency and vulnerability, which the taxonomy further decomposes into contact frequency, probability of action, threat capability, and resistance strength.
- Loss magnitude
Combines primary loss to the organization with secondary risk arising from the reactions of stakeholders such as customers, regulators, and partners.
- Risk analysis process
O-RA's scoping, data gathering, modeling, and reporting steps give analyses a consistent structure.
- Calibrated estimation and ranges
Factors are estimated as ranges with confidence rather than single points, and combined to produce a distribution of loss exposure.
- Companion guides and tools
The O-RA Process Guide, O-RT Example Guide, Mathematics for Open FAIR Guide, NIST CSF cookbook, and risk analysis tool support application.
- Certification for people
The Open FAIR Certification for People program validates analysts against the two standards.
Framework Scope
Open FAIR applies to any organization that wants to analyze information security and operational risk quantitatively, in any sector or region. The taxonomy and analysis standards address the definition and analysis of risk; they do not prescribe controls, which come from frameworks such as ISO/IEC 27001, NIST SP 800-53, and CIS Controls, and they do not replace the organization-wide risk management framework described by ISO 31000 or NIST SP 800-39. They are used by risk analysts, security leaders, and internal audit to prioritize and justify risk treatment decisions.
Framework Objectives
The standards exist so that information risk can be defined, analyzed, and communicated consistently in economic terms.
Provide a standard definition and taxonomy for information security risk.
Describe the process risk analysts follow to perform effective information security risk analysis.
Enable risk to be expressed as probable frequency and magnitude of loss rather than ordinal ratings.
Allow practitioners to quantify risk within other security standards and frameworks.
Support consistent, reviewable analyses through calibrated estimation and documented assumptions.
Underpin a certification program that validates analysts' competence.
Framework in Context
Open FAIR is the quantitative complement to the risk assessment processes in NIST SP 800-30 Rev. 1, ISO/IEC 27005, and ISO 31000 and the risk assessment techniques of ISO 31010; it supplies the taxonomy and analysis method those documents leave open. The Open Group publishes a cookbook for applying Open FAIR to the NIST Cybersecurity Framework, and the method is used to prioritize controls drawn from ISO/IEC 27001, NIST SP 800-53, and CIS Controls and to inform enterprise risk management under COSO ERM 2017. The FAIR Institute promotes the underlying FAIR model, while The Open Group holds the standards.
Common Framework Mappings
Open FAIR is commonly mapped to the risk management and assessment standards it quantifies and to the control frameworks whose priorities it informs.
Mapped frameworks include:
NIST SP 800-30 Rev. 1
ISO 27005:2022
ISO 31000:2018
ISO 31010:2009
NIST CSF 2.0
NIST SP 800-39
COSO ERM 2017
ISO 27001:2022
NIST 800-53 Rev.5
CIS Controls v8.1
- ClassificationCategoryRisk ManagementDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherThe Open Group
- VersioningVersionO-RT Version 3.1 (C251) and O-RA Version 2.1 (C250)Effective DateMay 22, 2025Issue DateMay 22, 2025
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
The O-RT and O-RA standards are published by The Open Group under its licence terms and are downloaded from its publications site with registration; their text is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports Open FAIR
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For Open FAIR, SmartSuite stores each scenario's taxonomy factors as ranges with their sources, holds the resulting loss exposure with its assumptions, and links scenarios to the controls and risk register entries they inform.
Risk Scenario Library
Hold assets, threat communities, loss events, and the O-RT factor estimates for every scenario in one structured record set.
Ownership, Cadence, and Accountability
Assign scenario owners and analysts, schedule re-analysis, and route results to risk committees through approval workflows.
Evidence Collection and Audit Trail
Attach data sources, calibration notes, and expert estimates to each factor with timestamps and reviewers.
Analysis and Exposure Tracking
Record loss exposure distributions and most-likely values, compare scenarios, and track exposure over time.
Risk and Control Alignment
Link scenarios to ISO/IEC 27001, NIST SP 800-53, and CIS controls and to the qualitative risk register so quantified and qualitative views stay consistent.
Executive Risk Reporting
Report loss exposure, control return on investment, and risk appetite comparisons to executives and the board.
Related frameworks

NIST SP 800-30 Rev. 1 is the NIST guide for conducting information security risk assessments: how to prepare, conduct, communicate, and maintain them at every tier of the organization.

ISO/IEC 27005:2022 provides guidance on identifying, analyzing, evaluating, and treating information security risks in support of an ISO/IEC 27001 ISMS.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO 31010:2009 provides guidance on selecting and applying risk assessment techniques to identify, evaluate, and manage organizational risks.

NIST SP 800-39 guides organizations to identify, assess, and manage information security risk at all enterprise levels.
Frequently Asked Questions For Open FAIR
Open FAIR is The Open Group's standard for quantitative information risk analysis, based on Factor Analysis of Information Risk. It consists of the Risk Taxonomy Standard (O-RT), which defines risk and its factors, and the Risk Analysis Standard (O-RA), which describes the process analysts follow.
O-RT Version 3.1 (document C251) and O-RA Version 2.1 (document C250), both published by The Open Group on May 22, 2025. They supersede O-RT Version 3.0.1 and O-RA Version 2.0.1 of November 2021.
Risk is the probable frequency and probable magnitude of future loss. Loss event frequency derives from threat event frequency and vulnerability, and loss magnitude combines primary loss with secondary risk, so each factor can be estimated and combined.
Those documents describe risk assessment processes but leave the analysis method open. Open FAIR supplies a taxonomy and quantitative method that fits inside them, and The Open Group publishes a cookbook for applying it to the NIST Cybersecurity Framework.
Yes. The Open FAIR Certification for People program, run by The Open Group, validates risk analysts' knowledge of the O-RT and O-RA standards.
The Open Group Security Forum publishes and maintains the standards. They are downloaded from The Open Group's publications site under its licence terms, and supporting guides and a risk analysis tool are also available there.
SmartSuite stores each scenario's factor estimates as ranges with their sources, holds loss exposure results with assumptions and dates, links scenarios to controls and the risk register, and reports exposure and control value to executives.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
