Domain 1: Risk Analysis Flashcards
- Valuable resources that need protection
- i.e. data, systems, people, buildings, property, etc.
Assets
- Potentially harmful occurrence
- i.e. hacker, earthquake, power outage, etc.
Threat
A weakness that can allow a threat to cause harm
Vulnerability
Formula to calculate risk:
Risk = Threat * Vulnerability
Variables that represent the severity of damage, sometimes expressed in dollars.
Impact
What other variable is sometimes added to the risk equation?
Risk = Threat * Vulnerability * Impact
Uses a quadrant to map the likelihood of a risk occurring against the consequences (or impact) that risk would have.
Risk Analysis Matrix
Calculation that allows you to determine the annual cost of a loss due to a risk.
Annualized loss expectancy (ALE)
The value of the assets you are trying to protect
Asset Value (AV)
Percentage (%) of value an asset loses due to an incident
Exposure Factor (EF)
- Calculated by AV * EF
- The cost of a single loss
Single-Loss Expectancy (SLE)
The number of losses suffered per year
Annual Rate of Occurrence (ARO)
- Calculated by SLE * ARO
- Yearly cost due to a risk
Annualized Loss Expectancy (ALE)
The overall cost associated with mitigation using a safeguard.
Total Cost of Ownership (TCO)
The amount of money saved by implementing a safeguard
Return on Investment (ROI)