// Capability Statement — Download PDF
Insights / Risk scoring
Methodology

AusperRiskIQ™: risk as a number that moves, not a letter that expires.

The standards already define risk as a living function of threats, vulnerabilities, likelihood, and impact. We take them at their word: five factors, computed continuously, defensible to an AO.

Ask a program how risky its system is and you will usually get an adjective. Low. Moderate. High. The adjective was chosen months ago, during categorization or at the last assessment, and it has not moved since — not when the scanner found new criticals, not when the POA&M slipped past its date, not when the evidence folder quietly went stale. The system changed; the adjective didn't. That is not risk management. That is risk taxidermy.

What the standards actually ask for

Here is the uncomfortable part for anyone defending the status quo: the letter-grade habit is not what the frameworks describe. NIST SP 800-30 defines risk as a function of threat events, the vulnerabilities they can exploit, the likelihood of occurrence, and the impact if they occur — four moving inputs, none of which sit still. FIPS-199 fixes the impact dimension — what a loss of confidentiality, integrity, or availability would cost the mission — and that part genuinely is stable. But impact is one axis, not the score. SP 800-39 frames risk management as a continuous, three-tier activity spanning organization, mission, and system. And SP 800-137 exists precisely because the authors knew point-in-time assessment decays: continuous monitoring is the mechanism that keeps the risk picture true between assessments. Add the modern threat layer — CVSS severity, CISA's Known Exploited Vulnerabilities catalog — and the standards, read together, describe something unmistakable: a computed quantity that changes when its inputs change.

Industry practice froze that quantity into paperwork because paperwork was all the tooling could carry. The frameworks never required the freeze. We think the tools should finally do what the documents say.

Our position

We hold a view some in this industry will call aggressive: a risk score an operator cannot decompose is not a score — it is a vibe. If the number cannot show its factors, cite its standards, and move the moment the environment moves, it should not be briefed to an Authorizing Official. RiskIQ is our answer: a continuous scoring model computed from the live authorization workspace, engineered so that every point in the number can be traced to a factor, every factor to a standard, and every change to an event.

The five factors

1 — Control exposure (up to 30 points · SP 800-30, SP 800-53). Failing controls are the vulnerability surface an assessor can already see. But a failing control is not a uniform unit of risk: a broken access-control or identity control opens the front door; a lapsed awareness-training control does not. RiskIQ weights failures by family criticality — access control, identification and authentication, system and communications protection, and system integrity carry the heaviest weights, configuration and audit families next, administrative families least. This mirrors how 800-30 treats predisposing conditions: severity depends on what the weakness exposes.

2 — Findings pressure (up to 30 points · SP 800-30, CVSS-informed). Open POA&M items are accepted, scheduled risk — and their pressure compounds with severity and with age. RiskIQ scores highs at eight points, moderates at three, lows at one, and multiplies any overdue item by half again. The overdue multiplier is deliberate and, we would argue, the most defensible line in the model: a missed remediation date is evidence about the organization, not just the finding. Likelihood of exploitation rises with exposure time; 800-30's likelihood axis demands that the score feel it.

3 — Evidence decay (up to 20 points · SP 800-137). A control marked satisfied with no artifact behind it, or an artifact nobody has refreshed, is a claim — not a fact. RiskIQ charges for stale evidence and for satisfied controls with empty evidence links, because continuous monitoring's entire premise is that assurance has a half-life. This is the factor most tools ignore entirely, and it is where packages quietly rot.

4 — Baseline completeness (up to 15 points · SP 800-53B). Planned-but-unimplemented controls are exposure someone signed up to carry. They weigh less than failures — a plan with a date is better than a surprise — but they weigh. A baseline that is 30 percent aspirational should not score like one that is built.

5 — Threat context (up to 8 points · CISA KEV, threat-informed defense). This factor prices the unknown. When live scan and log feeds are connected, the organization can see exploitation-relevant change, and the surcharge shrinks. When no feeds are connected, RiskIQ adds points — not because a threat was observed, but because nothing could have been observed. Blindness is a risk condition. Insurers have priced unknowns this way for centuries; risk scoring should too.

Reading the number

The factors sum to a 0–103 scale — deliberately not 100, because tidy round numbers imply a precision this discipline does not possess. Below 21 reads LOW: exposure is bounded, findings are managed, evidence is alive. Under 65 reads MODERATE: the posture is real but carrying debt — most operational systems under active development live here, and pretending otherwise helps no one. Above that is HIGH: the score is telling you where to look, factor by factor, and the honest response is remediation, not renegotiating the bands.

What makes the number useful to an Authorizing Official is not the value — it is the trajectory and the decomposition. A 52 falling week over week with the findings factor draining is a system being fixed. A 31 creeping upward on evidence decay is a package going stale under a green dashboard. Letters cannot say either of those things. A decomposed, moving score says both at a glance — and that is the same argument DoD's continuous-authorization push has been making at the policy level: the point-in-time snapshot is the artifact that has to go.

What RiskIQ deliberately is not

It is not dollarized risk. FAIR-style loss quantification is genuinely useful at board altitude, but translating control posture into annualized loss expectancy requires assumptions an ISSO cannot verify and an AO will not sign. We keep the score in the operator's units — controls, findings, evidence, feeds — because those are the units the operator can actually move. It is not an averaged CVSS either: averaging severity across a boundary launders the outliers that matter most. And it is not a compliance percentage wearing a costume — compliance measures conformance to a baseline; risk measures what the gaps and the unknowns can cost you. RiskIQ scores the second thing.

The full methodology document

This article is the argument; the document is the proof — 44 pages: the standards analysis in depth, every factor weight defended family by family, formal specification, worked arithmetic, objections answered, adoption guidance, and the assessor's reproduction protocol. The first five pages are open below; pages 6–44 unlock with an access code.

Methodology page 1Methodology page 2Methodology page 3Methodology page 4Methodology page 5
🔒 PAGES 6–44 LOCKED

Unlock the full document

Have an access code? Enter it for the instant download. No code? Request one below and we’ll email it to your business address.

No code? Request the document →

Where it runs

RiskIQ ships inside the Ausper Labs A&A console — every workspace computes it continuously, and clicking the score decomposes it, factor by factor, standard by standard. The scoring model described here is the production methodology; the data in the public prototype is illustrative. See it move in the next-generation GRC console.

Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper