Risk Management Concepts
Risk Management Concepts
Risk management is the process of identifying assets, the threats against them, and the vulnerabilities those threats could exploit — then reducing risk to a level the organization is willing to accept. You cannot eliminate risk; you manage it to an acceptable level.
- Asset — anything of value to the organization.
- Threat — a potential cause of an unwanted incident; a threat agent exploits a vulnerability.
- Vulnerability — a weakness a threat can exploit.
- Exposure — an instance of being susceptible to loss.
- Risk = likelihood x impact. Residual risk is what remains after controls.
Quantitative analysis
Quantitative risk analysis assigns money values so cost-benefit decisions can be defended. Learn these formulas cold — the exam calculates with them.
- SLE (single loss expectancy) = Asset Value x Exposure Factor.
- ALE (annualized loss expectancy) = SLE x ARO (annualized rate of occurrence).
- Value of a control = ALE before control − ALE after control − annual cost of control.
- Qualitative analysis uses ratings (high/medium/low), Delphi technique, and scenarios instead of dollars.
Responding to risk
- Mitigate (reduce) — implement a control.
- Transfer — buy insurance or contract the risk to a third party.
- Avoid — stop doing the risky activity.
- Accept — document and live with it, with management sign-off.
Control types
Controls are administrative, technical, or physical, and each functions as preventive, detective, corrective, deterrent, recovery, or compensating. A guard is physical; a policy is administrative; a firewall rule is technical.