6.4 Risk Assessment Models: CARVER, NIST SP 800-30, ISO 31000

Key Takeaways

  • The CARVER matrix evaluates target vulnerability across six factors: Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizability, assigning numeric scores from 1 to 10.
  • NIST SP 800-30 Rev 1 establishes a comprehensive four-step risk assessment process tailored for information systems and organization-wide risk management.
  • ISO 31000 provides an internationally recognized, high-level framework of principles, framework, and risk management processes applicable to any enterprise domain.
  • Selecting the appropriate model depends on facility vs. enterprise scope, regulatory mandates, physical vs. cyber environment, and organizational maturity.
Last updated: July 2026

6.4 Risk Assessment Models: CARVER, NIST SP 800-30, ISO 31000

To ensure consistency, repeatability, and rigor in risk evaluation, security managers rely on established risk assessment frameworks and standardized models. These methodologies range from tactical physical vulnerability matrix tools (such as CARVER) to comprehensive national and international enterprise risk standards (such as NIST SP 800-30 Rev 1 and ISO 31000).


The CARVER Matrix: Target Vulnerability Assessment

Originally developed by the U.S. military and intelligence community during the Vietnam War era and later adapted by government agencies (such as the USDA, DHS, and security agencies), the CARVER matrix is an offensive and defensive target vulnerability assessment tool. It allows security analysts to evaluate assets from an adversary's perspective to identify critical security vulnerabilities.

CARVER is an acronym for six evaluation factors scored on a scale from 1 (Lowest Vulnerability/Priority) to 10 (Highest Vulnerability/Priority):

The 6 CARVER Factors:

  1. C - Criticality: Measures how vital an asset is to the organization's core mission or operational capability. If destroying or disrupting the asset completely halts enterprise operations, Criticality scores 10.
  2. A - Accessibility: Evaluates how easily an adversary can physically or logically reach, enter, and approach the target asset. If a facility has open perimeter gates and unmonitored doors, Accessibility scores 10.
  3. R - Recuperability: Measures the time, financial effort, and operational difficulty required to replace, repair, or restore the asset back to full function following damage. If an asset requires a custom-built transformer taking 18 months to replace, Recuperability scores 10.
  4. V - Vulnerability: Assesses the susceptibility of the asset to destruction or disruption by a specific attack vector or threat capability. If existing physical or technical barriers cannot withstand an explosive or forced entry attempt, Vulnerability scores 10.
  5. E - Effect: Measures the broader operational, financial, psychological, economic, or legal ramifications resulting from a successful attack on the asset. If an attack induces widespread public panic or severe economic fallout, Effect scores 10.
  6. R - Recognizability: Evaluates how easily an adversary can identify and distinguish the asset as a high-value target among surrounding non-critical structures or decoy items. If a primary data center is marked with large exterior corporate signage, Recognizability scores 10.

CARVER Matrix Scoring Table Example:

Target AssetCriticality (1-10)Accessibility (1-10)Recuperability (1-10)Vulnerability (1-10)Effect (1-10)Recognizability (1-10)Total Score (Max 60)
Main Substation Transformer108978951 (High Risk)
Administration Office Annex39243526 (Low Risk)

Assets scoring highest across the CARVER matrix are prioritized for immediate physical hardening, redundant backups, and guard patrols.


NIST SP 800-30 Rev 1: Risk Assessment for Information Systems & Organizations

Published by the National Institute of Standards and Technology, NIST Special Publication 800-30 Revision 1 ("Guide for Conducting Risk Assessments") provides a structured, multi-step risk assessment methodology widely adopted across federal agencies, defense contractors, and private sector enterprises.

While originally created for information technology and federal systems, NIST SP 800-30 Rev 1 integrates seamlessly into physical and converged security programs.

The 4-Phase NIST Risk Assessment Process:

  +-------------------------------------------------------------+
  |              Step 1: Prepare for Assessment                 |
  | Scope, Purpose, Assumptions, Constraints, Threat Sources    |
  +-------------------------------------------------------------+
                                 |                       
                                 v                       
  +-------------------------------------------------------------+
  |              Step 2: Conduct Assessment                     |
  | Identify Threats/Vulnerabilities -> Determine Likelihood/  |
  | Impact -> Calculate Risk Level                              |
  +-------------------------------------------------------------+
                                 |                       
                                 v                       
  +-------------------------------------------------------------+
  |              Step 3: Communicate Results                    |
  | Share Risk Findings, Executive Reports, Treatment Plan      |
  +-------------------------------------------------------------+
                                 |                       
                                 v                       
  +-------------------------------------------------------------+
  |              Step 4: Maintain Assessment                    |
  | Continuous Monitoring, Update Risk Factors & Reports        |
  +-------------------------------------------------------------+
  1. Prepare for Assessment: Establish context by defining the assessment scope, organizational boundaries, analytical assumptions, risk tolerance thresholds, and sources of threat intelligence.
  2. Conduct Assessment: Identify threat events and vulnerabilities, determine the likelihood of occurrence, evaluate loss impact, and compute composite risk scores.
  3. Communicate Results: Formulate risk findings into executive reports and risk registers to inform executive decision-making.
  4. Maintain Assessment: Perform continuous monitoring of risk factors, tracking changes in the threat environment or control effectiveness to update assessments dynamically.

ISO 31000: Risk Management Guidelines

Developed by the International Organization for Standardization, ISO 31000 is the umbrella benchmark standard for enterprise-wide risk management. Unlike technical checklists, ISO 31000 provides generic principles and generic organizational frameworks applicable to any industry or security domain.

Core Components of ISO 31000:

  1. Principles: Risk management must create value, be integrated into organizational processes, form part of decision-making, explicitly address uncertainty, be structured, dynamic, tailored, and transparent.
  2. Framework: Leadership commitment, integration into corporate governance, designing the risk framework, implementing risk management, evaluating framework performance, and continual improvement.
  3. Process: A structured cycle comprising:
    • Establishing the Context: Defining internal and external organizational parameters.
    • Risk Assessment: Encompassing Risk Identification, Risk Analysis, and Risk Evaluation.
    • Risk Treatment: Selecting and implementing mitigation controls.
    • Monitoring & Review: Continually measuring risk performance.
    • Communication & Consultation: Engaging internal and external stakeholders throughout.

Comparative Summary of Risk Models

Model / StandardPrimary DomainScale / FocusPrimary Strength
CARVER MatrixPhysical facility & target vulnerabilityTactical asset level (1-10 scoring across 6 factors)Analyzes assets from an adversary's perspective; pinpoints physical gaps
NIST SP 800-30 Rev 1IT, cyber, and converged infrastructureSystem & operational level (4-step process)Highly structured, standardized, and repeatable risk assessment cycle
ISO 31000Enterprise-wide risk management (ERM)High-level strategic & governance levelGlobally accepted framework integrating risk into organizational decision-making
Test Your Knowledge

In the CARVER target vulnerability assessment matrix, what does the element "Recuperability" measure?

A
B
C
D
Test Your Knowledge

Which phase of the NIST SP 800-30 Rev 1 risk assessment process involves defining the assessment purpose, scope, assumptions, and sources of threat information?

A
B
C
D
Test Your Knowledge

Which international standard provides generic principles, an overarching framework, and a structured process for managing any form of risk across an entire enterprise?

A
B
C
D