NORA
How It Works

From Asset Owner's Answers
to Decisions Security Can Use

NORA closes the gap between the people who know your systems and the people who need to assess your risk — automatically, without requiring either side to learn the other's language.

The walkthrough below follows a risk assessment — the same guided method powers NORA's vendor and business justification assessments too.

Business Side
Asset Owner
→
NORA Engine
Guided Assessment
→
Translation Layer
Risk Scoring & Mapping
→
Security Side
Audit-Ready Output
01Business Side

Asset Owner Receives the Assessment

The process begins with the person who actually knows the system — the asset owner. They receive a plain-English interview designed around how they think about their work, not how a security framework describes it.

What This Covers

  • No cybersecurity background required
  • Questions framed in operational, business language
  • Covers access, data sensitivity, availability, vendor dependencies
  • Takes 20–40 minutes per application

The Difference in Approach

Traditional Assessment Asks

"Rate your exposure to lateral movement attacks on a scale of 1–5"

↓

NORA Asks

"Is this system accessible from outside your network, and do you know for certain your firewall rules are current?"

02NORA Engine

NORA Conducts a Structured Interview

NORA guides the asset owner through a structured conversation, asking follow-up questions based on their answers. Every response is mapped to the risk domains that security teams need — Likelihood, Impact, and Exposure.

  • Adaptive follow-up questions based on prior answers
  • Covers all relevant risk domains without jargon
  • Captures nuance that checkbox questionnaires miss
  • Flags gaps and uncertainties as explicit risk signals

Not Just

Yes/no on whether a control exists

But

Whether the owner can confirm the control is working — because uncertainty IS the exposure

NORA — Vendor Risk · Payroll Platform

NORA

When your payroll platform's support team accesses your data, are they using devices your organization manages, or their own personal devices?

You

They use their own laptops. We don't manage their device configuration.

NORA

That's useful context. Do you have any contractual requirement for them to meet specific security standards for devices that access your data?

Likelihood · Impact · Exposure
03Translation Layer

Business Knowledge Is Translated Into Risk Data

This is the core of what makes NORA different. The asset owner's answers — given entirely in business language — are automatically translated into the structured risk data that GRC professionals and auditors need.

  • Likelihood score derived from operational context
  • Impact score grounded in actual business consequences
  • Exposure score reflects control confidence, not just existence
  • Every score traceable back to specific asset owner statements

The Translation in Action

Asset Owner Said

"We only let a few people in from our office network, and I think the firewall is set up right but IT handles that"

NORA Translates

Becomes Structured Risk Data

L: ModerateE: High — unconfirmed controls

Impact scored by data type and user count. Exposure flagged as High because "I think" indicates control confidence cannot be established.

04Security Side

Security Teams Receive Audit-Ready Output

GRC professionals and auditors receive a complete, defensible risk assessment — not raw interview transcripts, but structured, scored, and narrated output that meets audit requirements without any additional translation work.

What the Security Team Receives

  • Composite risk score across Likelihood × Impact × Exposure
  • Narrative explanation written in audit-ready language
  • Compliance mapping to SOC 2, ISO 27001, PCI DSS, HIPAA, NIST CSF, and CSA CCM
  • Full traceability: every score tied to source responses

What Gets Delivered

Scored Risk Assessment

L×I×E composite score from 1–125 with severity classification and full methodology

Audit-Ready Narrative

Plain-English risk narrative traceable to specific asset owner statements

Framework Compliance Mapping

SOC 2, ISO 27001, PCI DSS, HIPAA, NIST CSF, and CSA CCM readiness derived automatically

Inside NORA

A NORA control-effectiveness view — systems measured against the organization's own security requirements

Control effectiveness at a glance: every system measured against your own security requirements — what you invested in, and what the assessments actually found.

Before and After NORA

The same assessment cycle. A fundamentally different outcome.

✕

Without NORA

  • ·Security team sends framework questionnaire to asset owner
  • ·Owner guesses or escalates to IT — answers reflect confusion, not reality
  • ·Security team spends hours re-interpreting and filling in gaps
  • ·Risk scores are generic, undefendable, and disconnected from operations
  • ·Audit failures or repeat cycles when assessments don't hold up
✓

With NORA

  • ·NORA sends a plain-English guided interview — owner answers comfortably in 30 minutes
  • ·Responses are grounded in operational reality, not guesswork
  • ·NORA automatically translates answers into structured risk scores
  • ·Security team receives a complete, narrated, traceable assessment
  • ·Output is audit-ready on day one — no revision cycle required
ONE METHOD

The Same Method, Three Assessments

You just saw a risk assessment. NORA applies the identical guided approach — a plain-English conversation, structured and translated — to every question your organization has to answer about its systems.

Risk Assessment

Is this system safe enough?

Vendor Assessment

Can we rely on this service provider?

Business Justification

Should we keep this asset, and how do we govern it?

See the Scoring Model Behind the Output

Understand how NORA scores Likelihood, Impact, and Exposure — and how those three dimensions combine into a single defensible risk score.