CISM - Information Security Risk Management - Section 2.3

Perform risk assessment and analysis using qualitative and quantitative methods.

Perform risk assessments using both qualitative risk analysis, such as risk matrices, and quantitative methods, including annual loss expectancy and single loss expectancy calculations. Choose the appropriate method based on data availability and audience, and interpret results to communicate risk in terms meaningful to business stakeholders.

Qualitative risk analysisQuantitative risk analysisRisk matrixALE/SLE

Practice question for this objective

Free sampleInformation Security Risk Managementhard

An information security manager is quantifying the annual loss expectancy for a customer database exposed to ransomware. The asset is valued at 4,000,000 pounds, the exposure factor for a successful ransomware event is estimated at 25 per cent, and historical and threat-intelligence data suggest such an event is likely twice per year. What is the annual loss expectancy that should be reported to support the business case for additional controls?

  • A1,000,000 pounds, calculated as the asset value multiplied by the exposure factor for a single occurrence.
  • B2,000,000 pounds, calculated as the single loss expectancy multiplied by the annualised rate of occurrence. Correct
  • C8,000,000 pounds, calculated as the asset value multiplied by the annualised rate of occurrence.
  • D500,000 pounds, calculated as the single loss expectancy divided by the annualised rate of occurrence.
Compute annual loss expectancy as single loss expectancy multiplied by the annualised rate of occurrence, where single loss expectancy is asset value times exposure factor. Annual loss expectancy expresses the expected yearly cost of a risk by chaining two steps: single loss expectancy captures the loss from one event as asset value times exposure factor, then the annualised rate of occurrence scales that single-event loss to the frequency expected over a year.

Why A is wrong: This is the single loss expectancy, not the annual loss expectancy; it ignores the annualised rate of occurrence of two events per year, so it understates the expected yearly loss.

Why B is correct: Single loss expectancy is 4,000,000 multiplied by 0.25, giving 1,000,000, and annual loss expectancy is the single loss expectancy multiplied by the annualised rate of occurrence of two, giving 2,000,000, which is the correct expected annual loss.

Why C is wrong: This multiplies the full asset value by the rate of occurrence and omits the exposure factor, which treats every event as a total loss of the asset and badly overstates the annual loss expectancy.

Why D is wrong: Dividing rather than multiplying by the rate of occurrence inverts the relationship; a higher event frequency must raise, not lower, the annual loss expectancy, so this is wrong.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.