ExamGecko
Question list
Search
Search

Question 37 - CISM discussion

Report
Export

Which of the following is the MOST important criterion when deciding whether to accept residual risk?

A.
Cost of replacing the asset
Answers
A.
Cost of replacing the asset
B.
Cost of additional mitigation
Answers
B.
Cost of additional mitigation
C.
Annual loss expectancy (ALE)
Answers
C.
Annual loss expectancy (ALE)
D.
Annual rate of occurrence
Answers
D.
Annual rate of occurrence
Suggested answer: C

Explanation:

= Annual loss expectancy (ALE) is the most important criterion when deciding whether to accept residual risk, because it represents the expected monetary loss for an asset due to a risk over a one-year period. ALE is calculated by multiplying the annual rate of occurrence (ARO) of a risk event by the single loss expectancy (SLE) of the asset. ARO is the estimated frequency of a risk event occurring within a one-year period, and SLE is the estimated cost of a single occurrence of a risk event. ALE helps to compare the cost and benefit of different risk responses, such as avoidance, mitigation, transfer, or acceptance. Risk acceptance is appropriate when the ALE is lower than the cost of other risk responses, or when the risk is unavoidable or acceptable within the organization's risk appetite and tolerance. ALE also helps to prioritize the risks that need more attention and resources.

Reference= CISM Review Manual, 16th Edition, Chapter 2: Information Risk Management, Section: Risk Assessment, page 831; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 22, page 242

asked 01/10/2024
Suman Konda
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first