Section 6: Risk Assessments Flashcards
Quantitative
Use of numerical values to determine asset values and projected loss
Qualitative
Use subjective judgment to determine asset values and projected loss
Asset Value (AV)
How much an asset is worth or costs to repair/replace
Exposure Factor (EF)
Percentage of potential loss
Single Loss Expectancy (SLE)
Cost of a single loss of an asset
Calculated through AV * EF
Annualized Rate of Occurrence (ARO)
Estimated number of a threat occurrence per year
Annualized Loss Expectancy (ALE)
Cost of overall loss per year
Calculated through SLE * ARO
Annual Cost of Safeguard (ACS)
Cost of a countermeasure for the asset
Cost Benefit Analysis Formula
(ALE1 - ALE2) - ACS
ACS - safeguard is $30,000
ALE 1 - $150,000 prior to implementation of safeguard
ALE 2 - $45,000 after implementation of safeguard
ALE 1 - ALE 2 = $105,000
$105,000 - $30,000 = $75,000 total savings
Delphi Technique
Anonymous survey process to encourage honest responses to help reach a consensus
Hybrid Analysis
Combining quantitative and qualitative results to perform a risk analysis
Security Control Assessment
Evaluate controls required to meet security objectives through system development
Privacy Control Assessment Steps
Prepare - identify objective, scope, timeframe, etc
Develop - identify which controls will be tested, get approval
Conduct - assess controls, create report
Analyze - review findings, address gaps