{"id":58018,"date":"2019-11-13T03:00:09","date_gmt":"2019-11-13T11:00:09","guid":{"rendered":"https:\/\/forescoutstage.wpengine.com\/?p=58018"},"modified":"2020-06-16T12:40:28","modified_gmt":"2020-06-16T19:40:28","slug":"the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time","status":"publish","type":"post","link":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/","title":{"rendered":"THE RIGHT SECURITY FRAMEWORK CAN HELP YOU SIMPLIFY YOUR RISK PLANNING: A simple, 3-step guide to determining your risk score one technical control at a time"},"content":{"rendered":"<p>In my recent blog, I recapped a conversation with Jack Jones, Chairman of the FAIR Institute and Gaurav Pal, CEO of stackArmor, where they debunked three myths about <a href=\"\/company\/blog\/ceo-to-ciso-how-to-debunk-the-myths-about-why-risk-management-is-difficult\/\">why risk quantification seems so difficult<\/a>. The reality is that each year threat actors become more savvy and the attacks they use become more sophisticated while corporate resources continue to shrink or remain the same. The gargantuan task of quantifying risk across the extended enterprise seems impossible for some. How do CISOs and their teams scope and tackle this task so that they can prioritize and get the best bang for their security or risk mitigation buck? Here&rsquo;s a three-step process our executive guests put together to simplify risk planning and mitigation:<\/p>\n<p><strong>Step 1: Use the NIST Cybersecurity Framework to scope what you need to measure<\/strong><\/p>\n<p class=\"center\"><img decoding=\"async\" src=\"\/wp-content\/uploads\/2019\/11\/risk-blog-11-13.png\"\/><\/p>\n<p>The simplest approach is to walk through each control family, one by one. For example, starting with the Identify Function, the first control within the Asset Management category is AM.1 Physical device inventory. Risk quantification does not have to be precise, but it should be accurate. An accurate assessment requires full device visibility across your extended enterprise of campus, cloud, OT, IoT and data center assets. To reduce downtime and operational overhead, use a tool that performs passive and active monitoring techniques to discover managed and unmanaged devices connecting to your heterogeneous network infrastructure.<\/p>\n<p><strong>Step 2:&nbsp; Use device visibility to provide inputs for your risk measurement process<\/strong><\/p>\n<p>Being able to see all devices exposes a whole world of potential vulnerabilities. Forescout&rsquo;s report, <em><a href=\"\/company\/resources\/forescout-healthcare-report\/\">Putting Healthcare Security Under the Microscope<\/a><\/em>, used actual healthcare device data from the Forescout Device Cloud to determine that many healthcare organizations are running legacy operating systems&mdash;many of which will be unsupported over the next few months.<\/p>\n<p>Knowing that the downtime associated with patching some critical care systems may be unacceptable, risk managers must now determine the level of risk they will accept, versus what they can and should mitigate. While being familiar with traditional managed devices is essential, unmanaged, and more importantly, unknown devices can become the doorway to introducing threat actors to the crown jewels on your network.<\/p>\n<p><strong>Step 3:&nbsp; Use the FAIR Methodology to provide a risk score <\/strong><\/p>\n<p>Now that you have a more detailed view of the devices on the network, you can classify those devices and use the FAIR methodology to examine the loss event frequency and loss magnitude of your most precious and critical assets. Analyze the probability of action and the financial and other impact that a breach via this device could have on your organization&rsquo;s reputation.&nbsp; What are the legal and regulatory implications from having a rogue device on your network? We explored that question in a previous blog, <a href=\"\/company\/blog\/can-a-rogue-device-cost-your-company-millions\/\">Can a rogue device cost your company millions<\/a>?<\/p>\n<p>The FAIR methodology transcends technical boundaries and allows you to quantify risk even in the OT\/ICS space. We also wrote about the <a href=\"\/company\/blog\/it-ot-convergence-conundrum-4-unique-challenges-that-increase-cyber-risk\/\">4 unique challenges that the IT-OT convergence<\/a> is creating for critical infrastructure companies. Another area of concern is shadow IT apps that can become the Trojan horse that opens the way for attackers to get access to your company&rsquo;s most valuable assets. We address cloud security risks head-on with a blog that describes the <a href=\"\/company\/blog\/how-can-cisos-effectively-tackle-shadow-it-apps-and-reduce-risk-in-the-cloud\/\">best practices that all CISO teams should know<\/a> to reduce risk in the cloud.<\/p>\n<p>For a deeper dive into the three steps above, watch this 6-minute video presented by our guest executives, Jack Jones and Gaurav Pal.<\/p>\n<p><script src=\"https:\/\/fast.wistia.com\/embed\/medias\/ed854lrl8x.jsonp\" async><\/script><script src=\"https:\/\/fast.wistia.com\/assets\/external\/E-v1.js\" async><\/script><\/p>\n<div class=\"wistia_responsive_padding\" style=\"padding:56.25% 0 0 0;position:relative;\">\n<div class=\"wistia_responsive_wrapper\" style=\"height:100%;left:0;position:absolute;top:0;width:100%;\"><span class=\"wistia_embed wistia_async_ed854lrl8x popover=true popoverAnimateThumbnail=true videoFoam=true\" style=\"display:inline-block;height:100%;position:relative;width:100%\">&nbsp;<\/span><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In my recent blog, I recapped a conversation with Jack Jones, Chairman of the FAIR Institute and Gaurav Pal, CEO of stackArmor, where they debunked three myths about why risk quantification seems so difficult. The reality is that each year threat actors become more savvy and the attacks they use become more sophisticated while corporate [&hellip;]<\/p>\n","protected":false},"author":77,"featured_media":58021,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[562],"tags":[],"coauthors":[423],"class_list":["post-58018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-views"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout<\/title>\n<meta name=\"description\" content=\"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout\" \/>\n<meta property=\"og:description\" content=\"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\" \/>\n<meta property=\"og:site_name\" content=\"Forescout\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ForescoutTechnologies\" \/>\n<meta property=\"article:published_time\" content=\"2019-11-13T11:00:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-06-16T19:40:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"560\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jannine Mahone\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@JannineMahoneFS\" \/>\n<meta name=\"twitter:site\" content=\"@Forescout\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\"},\"author\":{\"name\":\"Jannine Mahone\",\"@id\":\"https:\/\/www.forescout.com\/#\/schema\/person\/879243d9fd6c212d66dc37b0b1a94211\"},\"headline\":\"THE RIGHT SECURITY FRAMEWORK CAN HELP YOU SIMPLIFY YOUR RISK PLANNING: A simple, 3-step guide to determining your risk score one technical control at a time\",\"datePublished\":\"2019-11-13T11:00:09+00:00\",\"dateModified\":\"2020-06-16T19:40:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\"},\"wordCount\":611,\"publisher\":{\"@id\":\"https:\/\/www.forescout.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg\",\"articleSection\":[\"News &amp; Views\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\",\"url\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\",\"name\":\"The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout\",\"isPartOf\":{\"@id\":\"https:\/\/www.forescout.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg\",\"datePublished\":\"2019-11-13T11:00:09+00:00\",\"dateModified\":\"2020-06-16T19:40:28+00:00\",\"description\":\"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise\",\"breadcrumb\":{\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage\",\"url\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg\",\"contentUrl\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg\",\"width\":1024,\"height\":560,\"caption\":\"Blog: The Right Security Framework Can Help You Simplify Your Risk Planning: A Simple, 3-Step Guide to Determining Your Risk Score One Technical Control at a Time\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.forescout.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"THE RIGHT SECURITY FRAMEWORK CAN HELP YOU SIMPLIFY YOUR RISK PLANNING: A simple, 3-step guide to determining your risk score one technical control at a time\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.forescout.com\/#website\",\"url\":\"https:\/\/www.forescout.com\/\",\"name\":\"Forescout\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.forescout.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.forescout.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.forescout.com\/#organization\",\"name\":\"Forescout Technologies, Inc.\",\"url\":\"https:\/\/www.forescout.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.forescout.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/01\/forescout-logo.svg\",\"contentUrl\":\"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/01\/forescout-logo.svg\",\"width\":1,\"height\":1,\"caption\":\"Forescout Technologies, Inc.\"},\"image\":{\"@id\":\"https:\/\/www.forescout.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/ForescoutTechnologies\",\"https:\/\/x.com\/Forescout\",\"https:\/\/www.instagram.com\/forescouttechnologies\/\",\"https:\/\/www.linkedin.com\/company\/forescout-technologies\",\"https:\/\/www.youtube.com\/user\/forescout1\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.forescout.com\/#\/schema\/person\/879243d9fd6c212d66dc37b0b1a94211\",\"name\":\"Jannine Mahone\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.forescout.com\/#\/schema\/person\/image\/7f17a9d18285b540184e8e81e7800743\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d426cd9e4193bf7b0c5068105ee9a2397c6dd5ab493d479c8c12a792b1b4423d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d426cd9e4193bf7b0c5068105ee9a2397c6dd5ab493d479c8c12a792b1b4423d?s=96&d=mm&r=g\",\"caption\":\"Jannine Mahone\"},\"description\":\"An accomplished speaker, trainer and technology marketing professional, Jannine lives and breathes the exciting world of risk and compliance! She leads the Marketing Strategy for ForeScout\u2019s Compliance Solutions and recently led the development and publication of the industry\u2019s first comprehensive Compliance Guide. She is an active member of various Information Security groups and networks. With over a decade of Compliance product management, product marketing and product training experience at Cyber Security companies, Jannine has advised and interacted with hundreds of companies in every vertical. She resides in Houston, Texas with her family and pets.\",\"sameAs\":[\"https:\/\/x.com\/JannineMahoneFS\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout","description":"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/","og_locale":"en_US","og_type":"article","og_title":"The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout","og_description":"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise","og_url":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/","og_site_name":"Forescout","article_publisher":"https:\/\/www.facebook.com\/ForescoutTechnologies","article_published_time":"2019-11-13T11:00:09+00:00","article_modified_time":"2020-06-16T19:40:28+00:00","og_image":[{"width":1024,"height":560,"url":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","type":"image\/jpeg"}],"author":"Jannine Mahone","twitter_card":"summary_large_image","twitter_creator":"@JannineMahoneFS","twitter_site":"@Forescout","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#article","isPartOf":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/"},"author":{"name":"Jannine Mahone","@id":"https:\/\/www.forescout.com\/#\/schema\/person\/879243d9fd6c212d66dc37b0b1a94211"},"headline":"THE RIGHT SECURITY FRAMEWORK CAN HELP YOU SIMPLIFY YOUR RISK PLANNING: A simple, 3-step guide to determining your risk score one technical control at a time","datePublished":"2019-11-13T11:00:09+00:00","dateModified":"2020-06-16T19:40:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/"},"wordCount":611,"publisher":{"@id":"https:\/\/www.forescout.com\/#organization"},"image":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage"},"thumbnailUrl":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","articleSection":["News &amp; Views"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/","url":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/","name":"The Right Security Framework Can Help You Simplify Your Risk Planning - Forescout","isPartOf":{"@id":"https:\/\/www.forescout.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage"},"image":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage"},"thumbnailUrl":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","datePublished":"2019-11-13T11:00:09+00:00","dateModified":"2020-06-16T19:40:28+00:00","description":"Quantifying risk can seem daunting. Where to begin? Our 3-step guide shows how to start by using a common framework to structure and scope your risk measurement exercise","breadcrumb":{"@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#primaryimage","url":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","contentUrl":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","width":1024,"height":560,"caption":"Blog: The Right Security Framework Can Help You Simplify Your Risk Planning: A Simple, 3-Step Guide to Determining Your Risk Score One Technical Control at a Time"},{"@type":"BreadcrumbList","@id":"https:\/\/www.forescout.com\/blog\/the-right-security-framework-can-help-you-simplify-your-risk-planning-a-simple-3-step-guide-to-determining-your-risk-score-one-technical-control-at-a-time\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.forescout.com\/"},{"@type":"ListItem","position":2,"name":"THE RIGHT SECURITY FRAMEWORK CAN HELP YOU SIMPLIFY YOUR RISK PLANNING: A simple, 3-step guide to determining your risk score one technical control at a time"}]},{"@type":"WebSite","@id":"https:\/\/www.forescout.com\/#website","url":"https:\/\/www.forescout.com\/","name":"Forescout","description":"","publisher":{"@id":"https:\/\/www.forescout.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.forescout.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.forescout.com\/#organization","name":"Forescout Technologies, Inc.","url":"https:\/\/www.forescout.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.forescout.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/01\/forescout-logo.svg","contentUrl":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/01\/forescout-logo.svg","width":1,"height":1,"caption":"Forescout Technologies, Inc."},"image":{"@id":"https:\/\/www.forescout.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/ForescoutTechnologies","https:\/\/x.com\/Forescout","https:\/\/www.instagram.com\/forescouttechnologies\/","https:\/\/www.linkedin.com\/company\/forescout-technologies","https:\/\/www.youtube.com\/user\/forescout1"]},{"@type":"Person","@id":"https:\/\/www.forescout.com\/#\/schema\/person\/879243d9fd6c212d66dc37b0b1a94211","name":"Jannine Mahone","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.forescout.com\/#\/schema\/person\/image\/7f17a9d18285b540184e8e81e7800743","url":"https:\/\/secure.gravatar.com\/avatar\/d426cd9e4193bf7b0c5068105ee9a2397c6dd5ab493d479c8c12a792b1b4423d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d426cd9e4193bf7b0c5068105ee9a2397c6dd5ab493d479c8c12a792b1b4423d?s=96&d=mm&r=g","caption":"Jannine Mahone"},"description":"An accomplished speaker, trainer and technology marketing professional, Jannine lives and breathes the exciting world of risk and compliance! She leads the Marketing Strategy for ForeScout\u2019s Compliance Solutions and recently led the development and publication of the industry\u2019s first comprehensive Compliance Guide. She is an active member of various Information Security groups and networks. With over a decade of Compliance product management, product marketing and product training experience at Cyber Security companies, Jannine has advised and interacted with hundreds of companies in every vertical. She resides in Houston, Texas with her family and pets.","sameAs":["https:\/\/x.com\/JannineMahoneFS"]}]}},"featured_media_url":"https:\/\/www.forescout.com\/wp-content\/uploads\/2019\/11\/securtiy-framework-risk-blog.jpg","is_file":false,"excerpt_manually_set":false,"_links":{"self":[{"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/posts\/58018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/users\/77"}],"replies":[{"embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/comments?post=58018"}],"version-history":[{"count":0,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/posts\/58018\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/media\/58021"}],"wp:attachment":[{"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/media?parent=58018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/categories?post=58018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/tags?post=58018"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.forescout.com\/wp-json\/wp\/v2\/coauthors?post=58018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}