Security+
5.2Security Program Management and Oversight · 20% of exam

Explain elements of the risk management process

Risk identification, assessment types, analysis, register, appetite, response strategies, and business impact analysis.

Reading time
26 min read
Flashcards
22 cards
Practice questions
10 questions · 3 PBQs

The most substantial objective in Domain 5, and the only place on the exam where you do arithmetic. The formulas are short, they are tested directly, and they are free marks once memorised.

The quantitative formulas

Learn these three, in this order:

TermMeaningFormula
AVAsset Value — what the asset is worth
EFExposure Factor — % of value lost per incident
SLESingle Loss Expectancy — cost of one incidentSLE = AV × EF
AROAnnualised Rate of Occurrence — times per year
ALEAnnualised Loss Expectancy — cost per yearALE = SLE × ARO

Worked example. A server worth £40,000. A flood would destroy 50% of its value. Floods occur about once every four years.

  • EF = 0.5
  • SLE = 40,000 × 0.5 = £20,000
  • ARO = 1/4 = 0.25
  • ALE = 20,000 × 0.25 = £5,000 per year

Check yourself

An asset is worth £80,000. An incident would destroy 25% of it, and occurs twice per year. What is the ALE?

Why it matters: ALE tells you what a risk costs annually, so a control costing less than the ALE is worth buying and one costing more is not. That is the decision the numbers exist to support.

Qualitative vs quantitative

Quantitative

  • Numeric — money and probability
  • SLE, ALE, ARO
  • Objective, but needs reliable data

Qualitative

  • Descriptive — high, medium, low
  • Risk matrix of likelihood vs impact
  • Fast, but subjective

The tellNumbers means quantitative. High/medium/low means qualitative. Most organisations use both.

Risk assessment types

Ad hoc — as needed, triggered by an event. Recurring — on a schedule, e.g. annually. One-time — for a specific project or decision. Continuous — ongoing, automated monitoring.

The risk register

The central record of identified risks. Contains:

  • Risk description and its owner
  • Key risk indicators (KRIs) — metrics warning that a risk is increasing
  • Risk owner — the person accountable for managing it
  • Risk threshold — the level at which action becomes required
  • Current treatment and status

Risk appetite

How much risk the organisation is willing to take, expressed as a stance: expansionary (accepting more risk for growth), conservative (minimising), or neutral.

Risk tolerance

How much variation from that appetite is acceptable in practice.

The four risk responses

Every risk gets exactly one of these. Reliably tested.

Mitigate

  • Reduce likelihood or impact
  • Deploy a control

Transfer

  • Shift the financial consequence
  • Insurance, or contract to a third party

Avoid

  • Stop doing the risky activity
  • Cancel the project, exit the market

Accept

  • Take no action, knowingly
  • Documented, with sign-off

The tellInsurance is always transfer. Cancelling the activity entirely is avoid. Doing nothing WITH documentation is accept; doing nothing without it is negligence.

Exemption and exception are forms of acceptance — see 4.3. An exception is temporary and time-bound; an exemption is standing.

Check yourself

A company buys cyber insurance covering breach response costs. Which risk response is this?

Business impact analysis

A BIA determines what a disruption would cost and drives recovery objectives. Four metrics, and the exam tests all four:

RTO — Recovery Time Objective

How long you can be down. The maximum acceptable outage duration.

RPO — Recovery Point Objective

How much data you can afford to lose, measured in time. An RPO of one hour means backups at least hourly.

MTTR — Mean Time To Repair

Average time to restore a failed component. A measure of how quickly you recover.

MTBF — Mean Time Between Failures

Average time between failures. A measure of reliability.

Check yourself

A system must never lose more than 15 minutes of data. Which metric does this define?

Risk reporting

Communicating risk to those accountable — typically the board and senior management, who own risk appetite. Reporting turns the register into decisions.