DoCRA: The Duty of Care Risk Analysis Standard

What is DoCRA?
The Duty of Care Risk Analysis Standard is the nationally accepted risk assessment standard that balances an organization’s cost of security safeguards against the potential harm those risks pose to others, ensuring security measures are legally defensible, reasonable, and not overly burdensome. It is HALOCK’s standard for establishing reasonable security controls based on an organization’s mission, objectives, and obligations.
How much security is enough??
You know that risk can never be brought to zero. DoCRA, the Duty of Care Risk Analysis Standard, provides principles for evaluating risk and determining whether your safeguards are reasonable and can stand the test of legal action.
The method considers the likelihood and magnitude of harm to the organization and other affected parties, then weighs that risk against the burden created by safeguards. The objective is to select protections that reduce meaningful risk without imposing a burden greater than the risk they address.
HALOCK’s DoCRA services help organizations apply this reasoning to cybersecurity, compliance, governance, and risk decisions.
How Duty of Care Risk Analysis Works
A duty of care risk analysis asks:
- What harm could occur?
- Who could be affected?
- How likely is the harm?
- How significant could the impact be?
- What safeguards could reduce the risk?
- Is the burden of those safeguards reasonable compared with the risk they reduce?
The resulting risk-based decisions provide evidence of why the organization accepted a risk, selected a safeguard, or required additional treatment. This creates a more defensible basis for cybersecurity decisions than simply showing that a checklist was completed.
DoCRA Services to Support Compliance
HALOCK helps organizations apply DoCRA through several types of engagements.
DoCRA Risk Assessment
Organizations that need a complete DoCRA process can use HALOCK to conduct a risk assessment and develop corresponding treatment decisions. DoCRA can support risk analysis against requirements and frameworks including: HIPAA, GLBA, GDPR, 23 NYCRR Part 500, NIST, CIS Controls, ISO 27001, CCPA, PCI DSS, and other recognized standards.
The framework or regulation identifies requirements and control expectations. DoCRA helps determine whether the resulting safeguards are reasonable in light of actual risk.
Gap Assessment and Roadmap
A senior HALOCK teammate reviews the organization’s environment, mission, priorities, and approach to information security. Deliverables include a gap assessment and roadmap identifying the changes needed to implement DoCRA more fully. Our process evaluates how the organization’s current risk-management practices compare with the DoCRA Standard.
DoCRA Upgrade Services
Organizations with an existing risk program can transition their practices toward DoCRA without starting over. HALOCK works with executives and senior management to establish risk assessment and acceptance criteria, then reevaluates known risks using those criteria.
Evidence-based likelihood information, including HALOCK’s Industry Threat HIT Index where applicable, can help support those decisions. We then identify reasonable safeguards that reduce risk to an acceptable level.
DoCRA and Reasonable Security FAQs
How do DoCRA and CIS RAM work together?
DoCRA and CIS RAM serve different but complementary roles. DoCRA provides the principles for determining whether a safeguard is reasonable. CIS RAM applies those principles specifically to the CIS Controls through worksheets, criteria, and a repeatable assessment process. HALOCK helped develop CIS RAM with the Center for Internet Security, and Chris Cronin of HALOCK is the principal author of both DoCRA and CIS RAM.
What is Reasonable Security?
Reasonable Security means implementing safeguards proportionate to the risks they address. Security does not need to eliminate every possible risk, but decisions should be informed, documented, and defensible.
What is due care?
Due care describes the degree of protection a reasonable party would apply to prevent foreseeable harm to others.
What is an appropriate risk?
An appropriate risk is a risk that the organization, interested parties, and relevant authorities would reasonably consider acceptably low.
What are reasonable safeguards?
Reasonable safeguards reduce the likelihood or impact of harm without creating a burden disproportionate to the risk being reduced.
Why does documentation matter?
Documented analysis provides evidence of what risks were considered, how safeguards were evaluated, and why the organization determined its decisions were reasonable. The result is defensible cybersecurity based on documented judgment rather than an assumption that compliance with a control list alone proves appropriate security.
What are Examples of Reasonable Security Litigation Cases that Reference DoCRA?
Herff Jones Assurance of Voluntary Compliance, PA; pg.5 – DoCRA
Herff Jones Assurance of Discontinuance, NY; pg. 5 – DoCRA
DNA Diagnostics Assurance of Voluntary Compliance, OH; pg. 7 – DoCRA
Who authored DoCRA and CIS RAM?
The authors are CIS RAM and DoCRA:
- CIS RAM was originally developed by HALOCK Security Labs in partnership with the Center for Internet Security (CIS).
- The principal author of both DoCRA and CIS RAM is Chris Cronin (Partner at HALOCK Security Labs; Chair of the DoCRA Council).
- DoCRA itself is maintained by the DoCRA Council, a nonprofit body that includes CIS among its founding members.
How are “Reasonable Security,” CIS RAM, and DoCRA related?
Reasonable Security is the legal requirement. DoCRA defines how to judge what’s reasonable by balancing risk and burden, and CIS RAM applies DoCRA in practice so organizations can demonstrate that their security decisions are justified and defensible.
DoCRA and CIS RAM work together as a standard-and-method pair:
- DoCRA provides the principles for determining what is “reasonable,” guiding analysts to balance risk reduction with the burden of safeguards and the impact on all affected parties.
- CIS RAM applies those DoCRA principles directly to the CIS Critical Security Controls, giving organizations worksheets, criteria, and a repeatable process to evaluate risks and justify their security decisions.
- Need more? Here are 6 Ways DoCRA Can Help Establish Reasonable Security
ANALYZING RISK FOR REASONABLE AND APPROPRIATE SAFEGUARDS
What do these risk terms mean?
Glossary for DoCRA Terms and definitions aligned with legislation and requirements to establish reasonable security.
Appropriate risk: Risk that, as evaluated and stated, would appear to an organization, its interested parties, and authorities as acceptably low.
Assessing organizations: Organizations that analyze risks that they may pose to others.
Authorities: Usually, regulators or judges who may evaluate the reasonableness of safeguards as compared to harm to others and may impose penalties as a result of their evaluation.
Due care: A degree of protection that a reasonable person applies to protect others from harm.
Duty of care: The responsibility of one party to prevent harm to others.
Duty of Care Risk Analysis: Describes processes for evaluating risks and their safeguards so that the resulting analysis is easily communicated to and accepted by authorities – such as regulators and judges – and to other parties who may be harmed by those risks.
Executive Order 12866: Required the regulations to balance cost and benefit; controls must not cost more than the risk to others.
Impact: The magnitude of harm that may be suffered by any party as a result of a threat. It can be stated qualitatively and quantitatively.
Interested parties: Individuals or organizations that may benefit by engaging in risk or that may be harmed if risk is realized.
Likelihood: The frequency, commonality, or foreseeability of a threat creating an impact. It can be stated qualitatively and quantitatively.
Reasonable Person: Someone who thinks through the likelihood and impact of threats that might create harm and designs safeguards that are not more burdensome than those risks.
Reasonable safeguards: Protections against the foreseeability or magnitude of risks that do not pose a burden that is greater than the risk they protect against.
Risk Acceptance Criteria: The likelihood of an impact that the organization equates with appropriate risk.
Threat: An act or an omission that may create harm.
Vulnerability: A weakness or lack of a safeguard that may permit a threat to create harm.
Contact Us
