Section 9.86 Quantitative Risk Analysis Flashcards

Objective 5.2: Explain elements of the risk management process

1
Q

Quantitative Risk Analysis

A

Provides objective and numerical evaluation of risks

■ Used for financial, safety, and scheduling decisions

■ Utilises key components:
● Single Loss Expectancy (SLE)
● Exposure Factor (EF)
● Annualized Rate of Occurrence (ARO)
● Annualized Loss Expectancy (ALE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Exposure Factor (EF)

A

● Proportion of asset lost in an event (0% to 100%)

● Indicates asset loss severity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Single Loss Expectancy (SLE)

A

● Monetary value expected to be lost in a single event

● Calculated as Asset Value x Exposure Factor (EF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Annualised Rate of Occurrence (ARO)

A

● Estimated frequency of threat occurrence within a year

● Provides a yearly probability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Annualised Loss Expectancy (ALE)

A

● Expected annual loss from a risk

● Calculated as SLE x ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

You are managing a company’s IT infrastructure. One of your servers, valued at $20,000, has an Exposure Factor (EF) of 60% in the event of a crash. The server crashes once every five years.
What is the Annualized Loss Expectancy (ALE) for this server?

A

The Single Loss Expectancy (SLE) is calculated as the value of the asset multiplied by the Exposure Factor (EF). In this case, SLE =12,000. The Annualized Rate of Occurrence (ARO) is 1/5 (since the server crashes once every five years) = 0.2. The Annualized Loss Expectancy (ALE) is calculated as SLE * ARO. In this case, ALE= 12,000 * 0.2= 2,400.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly