100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Summary

Summary Risk Management Concepts

Rating
-
Sold
-
Pages
5
Uploaded on
16-10-2024
Written in
2022/2023

The Advanced Cybersecurity and Risk Management notes are from the University of Phoenix Advance Cybersecurity Certification course - these notes will assist you in understand different aspects and domains of Information Security. The notes will guide you through the process of understanding each domain to prepare you for future certification exams.

Show more Read less
Institution
Cyber Security Specialist
Course
Cyber Security Specialist









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Cyber Security Specialist
Course
Cyber Security Specialist

Document information

Uploaded on
October 16, 2024
Number of pages
5
Written in
2022/2023
Type
Summary

Content preview

Risk Management Concepts

Risk - the possibility that something could happen to damage, destroy, or
disclose data or other resources is known as RISK



Managing risk is an element of sustaining a secure environment



Risk Management is a detailed process of identifying factors that could
damage or disclose data, evaluating those factors in light of data value and
countermeasure cost, and implementing cost-effective solutions for
mitigating - to reduce the overall risk



Risk Terminology

Asset

Asset valuation

Threats

Vulnerability

Exposure

Risk

RISK=THREAT x VULNERABILITY

Safeguards

Attack

Breach

Identify threats and vulnerabilities - essential part of RM is identification and
examination of threats



Risk assessment/analysis - exercise for upper management to initiate and
support risk analysis and assessment by defining the scope and purpose

Quantitative Risk Analysis - concrete %'s

 What is the value of the asset - Asset value - AV

1

,  What are the possible threats to the asset - Exposure factor - EF

 If a threat was realized, what is the loss - Single Loss Expectancy SLE

 Calculate the likelihood of each threat being realized in a single year -
Annualized Rate of Occurrence - ARO

 Calculate overall loss potential per threat - Annualized Loss Expectancy
- ALE

Formulas

ALE = SLE x ARO

If an asset is valued at $200,000 and it has an EF of 45% for a specific threat,
then the SLE is $90,000

ALE before safeguard - ALE after implementing the safeguard - annual cost of
safeguard (ACS) = value of the safeguard to the company

ALE1 - ALE2 - ACS

Concept Formula

Exposure Factor - EF %

Single Loss Expectancy - SLE SLE = AV x EF

Annualized Rate of Occurrence - # / year
ARO

Annualized Loss Expectancy - ALE = SLE x ARO or ALE = AV x EF x
ALE ARO

Annual cost of Safeguard - ACS $ / year

Value or benefit of a safeguard (ALE1 - ALE2) - ACS



Calculating Safeguards

 Cost of purchase, development, and licensing

 Cost of implementation and customization


2
$5.99
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
jimb6056

Also available in package deal

Thumbnail
Package deal
Cybersecurity and Risk Management
-
30 2024
$ 179.70 More info

Get to know the seller

Seller avatar
jimb6056 (self)
View profile
Follow You need to be logged in order to follow users or courses
Sold
0
Member since
1 year
Number of followers
0
Documents
37
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions