OCTAVE
Operationally Critical Threat, Asset and Vulnerability Evaluation — a risk framework from Carnegie Mellon's CERT/SEI that works at the level of the organisation, not a single application. It starts from the assets the business can't afford to lose and builds a security strategy around protecting them.
What it is
OCTAVE is a self-directed, risk-based approach to information-security assessment and planning. Where STRIDE models one system's design, OCTAVE asks the organisational questions: what are our critical assets, what are they worth, what threatens them, and what is our strategy to protect them? It's driven by the business, with security supporting — reflecting the reality that operational risk is owned by leadership, not just IT.
Variants exist for different scales: the original OCTAVE, OCTAVE-S for smaller organisations, and OCTAVE Allegro, a streamlined version focused tightly on information assets.
The three phases
Identify the organisation's critical assets, what they're worth, current protections, and the threats against them — from the people who run the business.
Examine the technology that supports those assets and find the weaknesses an attacker could exploit to reach them.
Turn the risks into a prioritised mitigation strategy and concrete protection plans the organisation will actually execute.
How it works — the architecture
OCTAVE is self-directed and workshop-driven: an internal team, with facilitation, drives the analysis rather than outsourcing it to auditors. The focus is operational risk to the organisation's mission, balancing three dimensions — assets, threats and the vulnerabilities of the infrastructure that supports them. The output is a security strategy and risk-mitigation plan tied to business priorities, not just a list of technical defects.
How we audit your systems with OCTAVE
- We facilitate, you own it — workshops with your business and IT leaders to surface the assets and risks only they truly know.
- We anchor on critical assets — including AI systems and the data they touch, which are now operationally critical for many firms.
- We connect threats to infrastructure — mapping how a weakness in the stack could reach a crown-jewel asset.
- We deliver a strategy, not a list — a prioritised, executable protection plan aligned to your risk appetite.
How we implement it
OCTAVE fits when the question is bigger than one app — an organisation-wide security programme, a board mandate, or a regulated entity that needs a defensible enterprise risk posture. We run it alongside application-level threat modeling (STRIDE/PASTA) so the strategy at the top connects to concrete controls at the bottom, and we map the resulting plan to NIST AI RMF, ISO/IEC 42001 and the EU AI Act so it stands up to audit.
OCTAVE is a CERT/SEI (Carnegie Mellon) framework. This page reflects NexusFinLabs' practice and is general guidance, not legal advice.