Advancing Risk Management Capability Using the OCTAVE FORTE Process
Brett Tucker · Figshare · 2020
OCTAVE FORTE (Operationally Critical Threat, Asset, and Vulnerability Evaluation FOR The Enterprise) is a process model that helps executives understand and prioritize the complex risks affecting their organization. It also helps organizations identify, analyze, prioritize, and mitigate risks that could impact them. The Software Engineering Institute (SEI) developed the OCTAVE FORTE process model to help organizations evaluate their security risks and use ERM principles to bridge the gap between executives and practitioners. The process model guides organizations that are new to risk management in building an ERM program, and it helps mature organizations fortify their existing ERM program, making it more reliable, measurable, consistent, and repeatable. Besides describing the OCTAVE FORTE process, this report recommends methods and provides a sample risk management policy that organizations can refer to or adapt when writing their own policy. Supplemental materials contain templates that organizations can use when conducting many of the OCTAVE FORTE activities.