How were the default values of CounterMeasures determined? Were any non-formal standards or industry standards used?
In CounterMeasures, “default values” refers to pairings between countermeasures/threats, countermeasures/vulnerabilities, threats/vulnerabilities, vulnerabilities/asset groups, etc. and the specific factors of these relationships. In all of these cases, the type pairings are not available as standards.CounterMeasures default values were established based on the risk analysis, information security, and physical security experience of numerous industry experts. The initial defaults have undergone trial and adjustment over the years by many users in a wide variety of environments, including Commercial, Government (Federal, State, and Local), and numerous Department of Defense agencies. We do, however, use the national standards lab for threat frequency multipliers.