Risk Control Strategies

  1. Avoidance / Defend — Implement policies or technology to get rid of the risk
  2. Transfer — Buy insurance, let another more experienced company handle the risk
  3. Mitigation — Reduce the impact (buy anti-virus, come up with backup plans)
  4. Accept — Asset does not justify the cost of protection (perform cost benefit analysis)
  5. Terminate — Avoid activities that introduces uncontrollable risks

Quantitative & Qualitative Analysis

  • Quantitative: Use numbers & data
  • Qualitative: Other methods not using numbers & data

Cost Benefit Analysis

Cost

  • Cost of development/acquisition
  • Training fees
  • Implementation cost
  • Service cost

Single Loss Expectancy (SLE)

  • Formula:

Annualised Rate of Occurrence (ARO)

  • How often an attack is expected to successfully occur in a year.

Annualised Loss Expectancy (ALE)

  • Overall loss expected per risk incurred by an attack
  • Formula:

Cost Benefit Analysis Formula

  • ALE(prior) — Loss expectancy before implementation of risk control
  • ALE(post) — Loss expectancy after implementation of risk control
  • ACS — Annualised cost of safeguard
  • Formula: