Framework of Risk Management and Analysis (FoRMA)

A holistic, technology-independent approach to risk management developed since 2004

Since 2004
Battle-Tested
Industry Proven

Two Decades of Evolution

From concept to industry-proven framework, FoRMA has been refined through real-world applications

2004

Framework Development

Initial development of the FoRMA framework begins

2008

SecureForum Presentation

Presented at SecureForum in San Jose, California

2009

Lockheed Martin

Framework presented to Lockheed Martin

2004-Present

Real-World Application

Applied across Seagate Technologies, Latus Solutions, Take2, and more

Benefits of FoRMA

A comprehensive framework designed to transform how organizations approach risk management

Big Picture

FoRMA will help to provide a holistic vision and strategic understanding of the relationships of many of our current and familiar security models.

Technology Independent

FoRMA is flexible and can be applied to information security, physical security, even medical risk management.

Business Focused

FoRMA will demonstrate how to achieve business objectives by controlling risk to acceptable levels, not by maximizing security.

Framework Overview

A proven model focusing on balance and appropriate control

Core Principles

  • A proven model focusing on balance and appropriate control
  • An Open Framework for integrating industry standard models, such as CIA, STRIDE and others

Risk Elements

Threat
Vulnerability

Control Elements

Technology
Process

Interactive Framework Explorer

Click on each element to explore how FoRMA addresses risk and control

Risk Elements

Control Elements

Primary Goal

Risk Mitigation

Control risks within acceptable limits to support business objectives

Establish Your Boundaries

Define

Define relevant policies, standards and best-practices

Protect

Protect assets and resources in accordance with policy

Detect

Detect policy violations

Assure

Assure policy compliance

Build Your Foundation

Start from the ground level and work your way up!

Construct a strong security foundation to build your security policies, standards and best-practices. Use industry established security methodologies and codes of best practice to guide your standards and practices.

Security Implementation Phases

Assurance
Detection
Protection
Awareness

IT Security Layers

Information Security
Infrastructure Security
Application Security
Network Security
Physical Security

Comprehensive Coverage

A security foundation supporting all IT layers (including information, infrastructure, application, etc), and addressing each security implementation phase (Awareness, Protection, Detection, and Assurance).

Part of the Cybernetix Ecosystem

FoRMA is a core component of the Cybernetix and CyberAlchemy ecosystems, bringing together decades of risk management expertise with cutting-edge security frameworks.

Cybernetix
CyberAlchemy
FoRMA

Stay tuned for more tools and resources from the framework