RSK allows you to quantify risk quickly with the information at hand, and then refine risk measurements over time as you are able to add more information to the RSK process.

Security Tests with RSK
RSK is a powerful tool for security tests. Using RSK in vulnerability mode, the level of risk is indicated by the severity of vulnerabilities (asset value, threat probability, and controls not visible to the test are not considered).

Vulnerabilities are assigned values from the NIST National Vulnerability Database (NVDB) whenever possible. Composite RSK measurements for applications, computer systems, and networks are calculated from vulnerability measurements.

Risk Assessment with RSK
RSK in risk mode makes risk assessment easier and less expensive. RSK can provide meaningful risk assessments with very little information, and those assessments can be continuously refined as new information is added.

RSK in risk mode considers vulnerability severity, threat likelihood, asset value, and control effectiveness—but if some of that information is missing, RSK still produces indicative values (like taking a person's temperature & blood pressure are indicators of general health)

NMI LLC — RSK Risk Measurement

RSK is a process for continuous quantitative risk measurement. RSK has been used in thousands of security tests, risk assessments, and audits since NMI first introduced it in 1999.

RSK Improves Risk Management & Reduces Costs

An RSK Example

The following chart depicts the actual RSK measurements of a real company over more than two years. The RSK measurements are color coded to correspond to the Department of Homeland Security's threat warning system.

RSK risk measurements over time

Notice that the risk changes up and down over time. This is the result of two opposing forces, entropy and energy

In the example, every increase in risk is due to entropy: a new asset is added, or a new threat or vulnerability arises. Every decrease in risk is due to the addition of energy: the company secures an asset, fixes a vulnerability, or updates controls to mitigate a threat.

How RSK Works

RSK reduces all the factors related to risk to easy-to-understand numeric values between 1 and 100. RSK risk measurements have some important properties:

RSK achieves these properties using a mathematical and algorithmic process based on the following assumptions:

RAPID, RSK, STORM, and TrustPath are trademarks of NMI LLC.