Published in 2009 by The Open Group, the Open FAIR Risk Taxonomy has been touted as the first model to decompose risk down to its basic elements and define the relationship or effect those elements have on one another. FAIR simply and intuitively defines how risk works and provides the analytic model to quantify cyber risk in financial terms. The genesis of Factor Analysis of Information Risk (FAIR) began in 2000 when Jack Jones, a newly minted CISO at Nationwide Insurance, was seeking budget approval from his board. He was asked a very simple question “how much risk do we have?” The follow up question was just as simple “how much less risk will we have if we grant you the funding?” Jack was unable to answer these questions in quantitative, financial terms and resolved to be more prepared the next time. The result of Jack’s relentless pursuit for an intuitive and usable model to quantify cyber risk in economic terms has now become an industry standard ontology for quantifying cyber risk supported by The Open Group FAIR Analyst Certification program. This presentation will provide the audience with an overview of the FAIR ontology, showcase what is possible and familiarize them with the resources available for further learning and investigation. Attendees will learn about: ·The need for the information security community to speak a common language·The limitations of qualitative measurement·The elements that make the FAIR ontology unique ·How FAIR enables cost-effective cyber risk management·Resources available to support a FAIR quantitative risk practice within your program