Quantitative Risk Assessments Flashcards

1
Q

What is Quantitative Risk Assessments?

A

Based on numeric values.
Asset value (AV)
Exposure factor (EF) - percentage of asset value loss when negative incident occurs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Single Loss Expectancy (SLE)?

A

How much loss is experienced during one negative incident? Multiply asset value (AV) by the exposure factor (EF)

Asset value (AV) = $24,000
Exposure factor (EF) = 12.5%
$24,000 (AV) * 0,125 (EF)= $3,000 (SLE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Quantitative Risk Assessment

A

Annualized Rate of Occurrence (ARO) - expected number of yearly occurrences. Example: 2-3 times per year.

Annualized Loss Expectancy (ALE) - total yearly cost of bad things happening. ALE=SLE x ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Qualitative Risk Assessments

A

Based on subjective opinions regarding: *threat likelihood
*impact of realized threat.
Threats are given a severity rating.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Risk Register?

A

Organizations should have one (or more)

Centralized list risks, severities, responsibilities, and mitigations.

Generally considered qualitative. - example: severity or impact ratings * occasionally includes hard numbers (%,$)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Risk Heat Map?

A

Take risk severity levels and map visually by color.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Risk Matrix?

A

Table of risk details similar to a heat map but without colors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly