Frameworks / OCTAVE
Threat Modeling · Organisational

OCTAVE

Operationally Critical Threat, Asset and Vulnerability Evaluation — a risk framework from Carnegie Mellon's CERT/SEI that works at the level of the organisation, not a single application. It starts from the assets the business can't afford to lose and builds a security strategy around protecting them.

What it is

OCTAVE is a self-directed, risk-based approach to information-security assessment and planning. Where STRIDE models one system's design, OCTAVE asks the organisational questions: what are our critical assets, what are they worth, what threatens them, and what is our strategy to protect them? It's driven by the business, with security supporting — reflecting the reality that operational risk is owned by leadership, not just IT.

Variants exist for different scales: the original OCTAVE, OCTAVE-S for smaller organisations, and OCTAVE Allegro, a streamlined version focused tightly on information assets.

The three phases

Build asset-based threat profiles

Identify the organisation's critical assets, what they're worth, current protections, and the threats against them — from the people who run the business.

Identify infrastructure vulnerabilities

Examine the technology that supports those assets and find the weaknesses an attacker could exploit to reach them.

Develop security strategy & plans

Turn the risks into a prioritised mitigation strategy and concrete protection plans the organisation will actually execute.

How it works — the architecture

OCTAVE is self-directed and workshop-driven: an internal team, with facilitation, drives the analysis rather than outsourcing it to auditors. The focus is operational risk to the organisation's mission, balancing three dimensions — assets, threats and the vulnerabilities of the infrastructure that supports them. The output is a security strategy and risk-mitigation plan tied to business priorities, not just a list of technical defects.

How we audit your systems with OCTAVE

How we implement it

OCTAVE fits when the question is bigger than one app — an organisation-wide security programme, a board mandate, or a regulated entity that needs a defensible enterprise risk posture. We run it alongside application-level threat modeling (STRIDE/PASTA) so the strategy at the top connects to concrete controls at the bottom, and we map the resulting plan to NIST AI RMF, ISO/IEC 42001 and the EU AI Act so it stands up to audit.

OCTAVE is a CERT/SEI (Carnegie Mellon) framework. This page reflects NexusFinLabs' practice and is general guidance, not legal advice.

Need an organisation-wide AI & security risk posture?