★ Starred in your notes: "study": asset value · exposure factor · SLE · ARO (SLE × ARO = ALE).
Breakdown 1 — Identify, then assess
From class — risk identification: know your assets; threat assessment (e.g., supply-chain failure — the vendor stops selling a part); risk register; likelihood of the risk occurring → risk matrix (likelihood × impact heat map); then accept / avoid / mitigate.
| Assessment type | When |
|---|---|
| Ad hoc | One-off, in response to an event/question |
| Recurring | On a schedule (annual) |
| One-time | For a project/acquisition |
| Continuous | Automated, ongoing (scanners, KRIs) |
Breakdown 2 — Analysis: qualitative vs. quantitative
| Qualitative | Quantitative | |
|---|---|---|
| Output | Not money — like a survey (class): High/Medium/Low, heat map | Value, money (class): dollars |
| Inputs | Expert judgment, probability/likelihood and impact ratings | Asset value (AV), exposure factor (EF), ARO |
| Use | Fast, broad prioritization | Justify spending: is the control cheaper than the expected loss? |
The formulas (class: "study"):
- SLE = AV × EF — single loss expectancy: cost of one occurrence.
- ALE = SLE × ARO — annualized loss expectancy: expected cost per year.
- ARO — annualized rate of occurrence (once every 4 years = 0.25).
Worked example: server worth $200,000, a flood destroys 25% (EF 0.25) → SLE = $50,000. Floods happen once per 4 years (ARO 0.25) → ALE = $12,500/yr. A $10,000/yr flood control is worth it; a $20,000/yr one isn't.
Breakdown 3 — Register, tolerance, appetite
| Term | Meaning |
|---|---|
| Risk register | The list of risks with owner, likelihood, impact, score, treatment, status |
| Key risk indicators (KRIs) | Metrics that warn a risk is rising (unpatched hosts, failed logins) |
| Risk owner | Person accountable for managing a specific risk |
| Risk threshold | The score above which action is required / escalation happens |
| Risk tolerance | How much variance from the appetite the org will accept for a given activity |
| Risk appetite | Threshold — what risk are you willing to take on (class); expansionary (take more risk for growth), conservative (minimize), neutral |
Breakdown 4 — Risk management strategies (class list + exam list)
| Strategy | Meaning | Example |
|---|---|---|
| Transfer (share) | Shift financial impact to someone else — insurance (class), outsourcing/cloud contracts | Cyber insurance |
| Accept | Live with it; exemption (control not required) or exception (temporary, documented deviation) | Low-value risk, or patch not yet available |
| Avoid | Stop the activity that creates the risk | Don't store card numbers at all |
| Mitigate | Reduce likelihood/impact with controls | Patch, MFA, backups |
| Deter (class) | Discourage the threat actor | Warning banners, guards |
Risk reporting: to the right audience (board = heat map/top risks; ops = register detail).
Breakdown 5 — Business impact analysis (BIA)
The BIA identifies critical processes and what downtime costs, producing the recovery targets:
| Metric | Meaning |
|---|---|
| RTO | Max time to restore |
| RPO | Max data loss (time) |
| MTTR | Mean time to repair |
| MTBF | Mean time between failures (repairable) |
| MTTF | Mean time to failure (non-repairable — light bulb) |
Exam tip: "Bought insurance" → transfer. "Discontinued the risky service" → avoid. "Documented that the legacy app runs unpatched until Q3" → accept (exception). "Which analysis gives dollar figures?" → quantitative. "Survey of managers rating risks High/Med/Low" → qualitative. Always compute SLE first, then ALE.
Quick self-check
- AV $1M, EF 10%, ARO 2/yr → SLE? ALE? ($100k; $200k.)
- Appetite vs. tolerance? (Appetite = overall willingness; tolerance = acceptable deviation per activity.)
- Exemption vs. exception? (Not required vs. temporary approved deviation.)
Sources: 20260917_173145.jpg, 20260917_173229.jpg, 20260917_173234.jpg