Risk Assessment and Treatment Decisions
An important use of risk assessments is to inform a cost-benefits decision about how to deal with a particular risk or a set of related risks.
8 slides · 5 min read · Domain 1
Clearly it is not in the organization's best interests, in most cases, to spend far more money, time, and effort mitigating, avoiding, or transferring a risk than the worst possible impact could be. Even a decision to accept a risk should be informed by this sort of tradeoff.
One traditional method for selecting the appropriate security controls has been the use of the "loss expectancy" model for assessing the risk. This model uses an annualized value for the expected rate of occurrence, and multiplies it by the expected losses or magnitude of the impact of a single such risk event, to calculate the annual loss expectancy:
ALE = SLE X ARO
The annualized rate of occurrence (ARO) is the number of times per year a given impact is expected, expressed as a number. The single loss expectancy (SLE) is the expected impact related to a particular risk (the risk being assessed). Most often, this is expressed monetarily. It is calculated by determining the asset value (AV) that might be affected (or lost) and multiplying it by the exposure factor (EF), a fraction (less than 1) that represents the amount of damage resulting from that type of loss:
SLE = AV X EF
Recall that the asset value may be its original procurement cost, its estimated replacement cost, or its total potential earnings for the organization.
For example, consider an intellectual property protection situation in which a new algorithm being considered for patent protection might, for example, have required a million-dollar investment in research, development and test to produce, but it is expected to produce over one hundred times that amount in new product revenues over the near-term future.
These simple calculations can help the organization make better-informed decisions about risks, as can be seen in a simple example.
Suppose that you own a cellphone worth $200 and you know you usually break your screen once every 9 months with a resulting damage of 30% of the total price of the phone. Does it make sense for you to buy screen protection insurance that costs $4.99 per month?
Let's check the numbers:
Asset value: $200 (cellphone price)
Exposure value: 30% of cellphone price (cost of replacing screen) So a single incident will cost us:
200 × 30% = $60.00 (SLE)
Annual rate of occurrence:.75 (one breakage every 9 months)
Thus, the annual loss expectancy is:
ALE = 60 x.75 = $45.00
Offered insurance annual cost is $59.88.
Obviously, this is a very simple example, but let's review the risk management options using this example data from the ALE:
RISK MITIGATION
The ALE is $45. A second (backup) phone would probably cost $200, which on cost grounds alone rules this option out.
RISK AVOIDANCE
If we choose not to have a cellphone, we will avoid the risk but it will not allow us to do our job; risk avoidance, in this case, does not make much sense.
RISK TRANSFERENCE
The ALE is $45, and the cost of transferring is $59.88; risk transference is a rational option.
RISK ACCEPTANCE
If the insurance was $99 per year, the risk mitigation and risk transference would make financial sense. Risk avoidance is still not an ideal option. We will accept the risk not buy the insurance.
NOTE:
The ALE is a rudimentary and mature model, An organization that has repeated, inherited from the realm of physical security, continuous losses related to data/IT will and is well suited to examples of this kind. It soon be beleaguered by regulators, service is not particularly apt for IT security: in our providers, and customers alike. So, this field, there is no good way to assess SLE; a model doesn't work well for IT security. However, it is still used throughout the loss event is rarely nominal, moreover, we are typically not allowed to have an ARO industry and is an aspect of security that other than 1-whenever a vulnerability is the candidate is required to understand discovered because a loss has been realized, as part of the CBK. we are required to take steps to remediate that vulnerability so that specific type of loss should not be repeated.
Can ALE and SLE be Realistic for Information Systems?
Caution is advised, however. The simple ALE model, inherited from the realm of physical security, is mature and well understood in that realm and is well-suited to examples of this kind. It is not particularly apt for IT security for large, complex systems for which there is no good way to assess SLE, and a loss event is rarely nominal.
Operationally, management may not allow an ARO other than 1 (one occurrence per year), especially when the associated vulnerability is discovered after an incident has occurred and a loss has been suffered.
In such circumstances, IT and security personnel are often required to take immediate steps to remediate that vulnerability so that specific type of loss should not be repeated. An organization that has repeated, continuous losses related to data or its IT infrastructures and systems will soon be beleaguered by regulators, service providers, and customers alike.
All that notwithstanding, the ALE model is still in widespread use throughout the information security industry and is something that security professionals should be familiar with as a basic principle. It's a starting point on your journey toward quantitative risk assessment, rather than the destination.
