Qualitative and Quantitative Risk Flashcards

1
Q

What type of methods are used for Qualitative Analysis?

A

Intuition, experience, and other methods to assign a risk value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What analysis method uses numerical and monetary values to calculate risk?

A

Quantitative analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which method of analysis can calculate a direct cost for each risk?

A

Quantitative analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define the Magnitude of Impact

A

An estimation of the amount of damage that a negative risk might achieve

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the three most common calculation methods used to calculate risk in security?

A

Single Loss Expectancy (SLE)
Annualized Rate of Occurrence (ARO)
Annualized Loss Expectancy (ALE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define Single Loss Expectancy and state the formula

A

The cost associated with a threat that occurred. Essentially the amount lost if bad happens.

Asset Value (AV) * Exposure Factor (EF) = SLE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define Annualized Rate of Occurrence (ARO)

A

The number of times a year a threat will occur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Annual Loss Expectancy?

A

The expected cost of realized threat over a given year.

Annual Loss Expectancy (ALE) = Single Loss Expectancy (SLE) * Annual Rate of Occurrence (ARO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why is the ALE important?

A

It’s an important part of decision making.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly