Skip to content

ITIS-468-47605: Certified Information Systems Security Professional (CISSP) Cert Exam Prep

Fall 2026

Risk Management Concepts

Risk Management Concepts

Risk management is the process of identifying assets, the threats against them, and the vulnerabilities those threats could exploit — then reducing risk to a level the organization is willing to accept. You cannot eliminate risk; you manage it to an acceptable level.

  • Asset — anything of value to the organization.
  • Threat — a potential cause of an unwanted incident; a threat agent exploits a vulnerability.
  • Vulnerability — a weakness a threat can exploit.
  • Exposure — an instance of being susceptible to loss.
  • Risk = likelihood x impact. Residual risk is what remains after controls.

Quantitative analysis

Quantitative risk analysis assigns money values so cost-benefit decisions can be defended. Learn these formulas cold — the exam calculates with them.

  • SLE (single loss expectancy) = Asset Value x Exposure Factor.
  • ALE (annualized loss expectancy) = SLE x ARO (annualized rate of occurrence).
  • Value of a control = ALE before control − ALE after control − annual cost of control.
  • Qualitative analysis uses ratings (high/medium/low), Delphi technique, and scenarios instead of dollars.

Responding to risk

  • Mitigate (reduce) — implement a control.
  • Transfer — buy insurance or contract the risk to a third party.
  • Avoid — stop doing the risky activity.
  • Accept — document and live with it, with management sign-off.

Control types

Controls are administrative, technical, or physical, and each functions as preventive, detective, corrective, deterrent, recovery, or compensating. A guard is physical; a policy is administrative; a firewall rule is technical.

Figure 1 — the risk management lifecycle.