forced ranking optimization
Term · Cybersecurity · MLC-T-CYB-001779
Prioritizing risks in the way that will best use available resources to achieve the maximum benefit given specific negative and positive consequences. Various business drivers and risk consequences have differing weights for developing a score, helping to move beyond the simplistic “threat multiplied by vulnerability” approach to build business objectives into that equation. Because these factors and their weights are based on business drivers, the factors should be defined by senior stakeholders but can be applied at all levels of the enterprise, subject to adjustment and refinement. Notably, while forced ranking is often the default method of optimization, the methods above are equally valid and beneficial to the enterprise.
| Identifier | MLC-T-CYB-001779 |
|---|---|
| Field | Cybersecurity |
| References | NISTIR 8286B-upd1; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-001779",
"term": "forced ranking optimization",
"field": "Cybersecurity",
"definition": "Prioritizing risks in the way that will best use available resources to achieve the maximum benefit given specific negative and positive consequences. Various business drivers and risk consequences have differing weights for developing a score, helping to move beyond the simplistic “threat multiplied by vulnerability” approach to build business objectives into that equation. Because these factors and their weights are based on business drivers, the factors should be defined by senior stakeholders but can be applied at all levels of the enterprise, subject to adjustment and refinement. Notably, while forced ranking is often the default method of optimization, the methods above are equally valid and beneficial to the enterprise.",
"references": [
"NISTIR 8286B-upd1",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/forced-ranking-optimization/"
}
Record 1,779 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.