Why pick a framework at all
A framework gives you a defensible vocabulary, a repeatable process, and the ability to roll risk up to the board without re-inventing the methodology every quarter. The right choice depends on your sector, regulator and the type of risk you need to quantify.
The five frameworks compared
NIST RMF (SP 800-37 Rev 2)
- Best for: US-aligned organisations, federal supply chains, defence
- Strengths: Tight integration with NIST 800-53 controls, continuous-monitoring built-in
- Watch-outs: Heavy documentation; needs tailoring outside the US public sector
ISO/IEC 27005:2022
- Best for: ISMS-driven organisations, ISO 27001 certification, GCC regulators
- Strengths: Vendor-neutral, integrates cleanly with ISO 27001 risk requirements
- Watch-outs: Methodology-agnostic — you still need to pick qualitative or quantitative scoring
FAIR (Factor Analysis of Information Risk)
- Best for: Quantifying cyber risk in financial terms for boards and insurers
- Strengths: Defensible loss-event maths, executive-friendly outputs
- Watch-outs: Requires data — loss tables, threat-event frequency, vulnerability data
COSO ERM (2017)
- Best for: Enterprise risk reporting, audit-committee oversight
- Strengths: Aligns with internal-controls reporting, integrates with SOX
- Watch-outs: Not cyber-specific — pair with NIST CSF or ISO 27005
OCTAVE Allegro
- Best for: Asset-centric workshops in mid-sized organisations
- Strengths: Quick to run, business-owner friendly
- Watch-outs: Less rigorous than FAIR for board-level loss quantification
A decision tree
- Is your primary driver a certification (ISO 27001, SOC 2, ADHICS, CBUAE)? → ISO 27005
- Do you report to a US federal customer? → NIST RMF
- Does the board want cyber risk in dollars? → FAIR
- Are you consolidating financial, operational and cyber risk? → COSO ERM as the umbrella with FAIR or ISO 27005 underneath
- Do you need a 6-week pilot? → OCTAVE Allegro
What about AI risk?
ISO/IEC 23894:2023 and NIST AI RMF 1.0 extend the same lifecycle to AI systems. Use them alongside — not instead of — your existing cyber risk framework.
Common implementation mistakes
- Switching frameworks before completing one full annual cycle
- Treating the risk register as a spreadsheet rather than a workflow
- Skipping the risk-appetite statement
- Letting risk owners be IT, not the business
Next step
MAST runs framework-selection workshops as a one-day engagement. Book a workshop to walk your top 20 risks through three methodologies side-by-side.