CISM - Information Security Risk Management (20% of the exam) - Section 2.3

Perform risk assessment and analysis using qualitative and quantitative methods.

Perform risk assessments using both qualitative risk analysis, such as risk matrices, and quantitative methods, including annual loss expectancy and single loss expectancy calculations. Choose the appropriate method based on data availability and audience, and interpret results to communicate risk in terms meaningful to business stakeholders.

Qualitative risk analysisQuantitative risk analysisRisk matrixALE/SLE

Practice question for this objective

Free sampleInformation Security Risk Managementhard

An information security manager is quantifying the annual loss expectancy for a customer database exposed to ransomware. The asset is valued at 4,000,000 pounds, the exposure factor for a successful ransomware event is estimated at 25 per cent, and historical and threat-intelligence data suggest such an event is likely twice per year. What is the annual loss expectancy that should be reported to support the business case for additional controls?

  • A1,000,000 pounds, calculated as the asset value multiplied by the exposure factor for a single occurrence.
  • B2,000,000 pounds, calculated as the single loss expectancy multiplied by the annualised rate of occurrence. Correct
  • C8,000,000 pounds, calculated as the asset value multiplied by the annualised rate of occurrence.
  • D500,000 pounds, calculated as the single loss expectancy divided by the annualised rate of occurrence.
Compute annual loss expectancy as single loss expectancy multiplied by the annualised rate of occurrence, where single loss expectancy is asset value times exposure factor. Annual loss expectancy expresses the expected yearly cost of a risk by chaining two steps: single loss expectancy captures the loss from one event as asset value times exposure factor, then the annualised rate of occurrence scales that single-event loss to the frequency expected over a year.

Why A is wrong: This is the single loss expectancy, not the annual loss expectancy; it ignores the annualised rate of occurrence of two events per year, so it understates the expected yearly loss.

Why B is correct: Single loss expectancy is 4,000,000 multiplied by 0.25, giving 1,000,000, and annual loss expectancy is the single loss expectancy multiplied by the annualised rate of occurrence of two, giving 2,000,000, which is the correct expected annual loss.

Why C is wrong: This multiplies the full asset value by the rate of occurrence and omits the exposure factor, which treats every event as a total loss of the asset and badly overstates the annual loss expectancy.

Why D is wrong: Dividing rather than multiplying by the rate of occurrence inverts the relationship; a higher event frequency must raise, not lower, the annual loss expectancy, so this is wrong.

See more CISM practice questions, answers explained.

Exam traps in Information Security Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • 1,200,000 pounds, calculated by deducting the lost proportion from the full asset value to show what survives the event.

    Why it is wrong: Tempting because it uses the same figures, but this gives the residual asset value rather than the loss, so it misstates the single loss expectancy.

  • Escalate the breached KRI to the committee and recommend an immediate emergency budget allocation to drive the indicator back below its threshold before the next reporting cycle.

    Why it is wrong: It is tempting because a breached KRI feels like it demands urgent spending, but reacting to the indicator alone, without weighing it against appetite, can misallocate resources to a risk the organisation has already accepted.

  • The method cannot identify which assets are exposed because it omits any structured discovery of threats and vulnerabilities.

    Why it is wrong: This is tempting because qualitative methods are less rigorous, but threat and vulnerability identification precedes and feeds the matrix; the matrix scores identified scenarios rather than failing to find them.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.