Qualitative and Quantitative Risk Flashcards
What type of methods are used for Qualitative Analysis?
Intuition, experience, and other methods to assign a risk value.
What analysis method uses numerical and monetary values to calculate risk?
Quantitative analysis
Which method of analysis can calculate a direct cost for each risk?
Quantitative analysis
Define the Magnitude of Impact
An estimation of the amount of damage that a negative risk might achieve
What are the three most common calculation methods used to calculate risk in security?
Single Loss Expectancy (SLE)
Annualized Rate of Occurrence (ARO)
Annualized Loss Expectancy (ALE)
Define Single Loss Expectancy and state the formula
The cost associated with a threat that occurred. Essentially the amount lost if bad happens.
Asset Value (AV) * Exposure Factor (EF) = SLE
Define Annualized Rate of Occurrence (ARO)
The number of times a year a threat will occur
What is Annual Loss Expectancy?
The expected cost of realized threat over a given year.
Annual Loss Expectancy (ALE) = Single Loss Expectancy (SLE) * Annual Rate of Occurrence (ARO)
Why is the ALE important?
It’s an important part of decision making.