Please enable JavaScript.
Coggle requires JavaScript to display documents.
Risk Analysis (More Risk Terms (Residual Risk ((Total Risk) x control gap)…
Risk Analysis
More Risk Terms
Acceptable Risk
Residual Risk
(Total Risk) x control gap
Risk Management
Risk Analysis
Total Risk
Threats x Vulnerability x Asset Value
Qualitative
Valid but descriptive
Instead of Measurable
Opinions
Typically produced when
Limited expertise
short time frame
low amount of data
long-term employees
significant business experience
Consequence Terms
Negligible (1)
Marginal (2)
Important (3)
Critical (4)
Catastrophic (5)
Occurrence Terms
Frequent (A)
Probable (B)
Occasional (C)
Remote (D)
Improbable (E)
Quantitative
Facts
Terms
Asset Value
Value to organization
Consider more than capital cost
Exposure Factor
% of asset loss caused by ID'ed threat
Single Loss Expectation
Asset Value x Exposure Factor
Annual Rate of Occurence
Expected times / Number of years
Annual Loss Expectation
ALE = SLE x ARO
Calculated to determine if cost is worth it
Results
Monetary Values
Possible/Significant Threats
Probability rate
Yearly loss potential
Reccomendations
Safeguards
Countermeasures
Actions
All IT Systems have risk
Cant eliminate 100%