Quantitative Risk Formulas: SLE, ARO and ALE
The five quantitative risk formulas in the order they run, worked end to end from asset value to a funded decision, plus where the method breaks down.
The governance domain, and the largest in the exam outline: how an organisation decides what to protect, how much risk it will carry, which laws and standards bind it, and how it proves it acted with due care. Everything else in the CISSP sits inside decisions made here.
The ISC2 CISSP exam outline lists these areas for Domain 1 and gives the domain a weighting of 16%. The wording below is a plain-English paraphrase; the outline itself is the source.
The five quantitative risk formulas in the order they run, worked end to end from asset value to a funded decision, plus where the method breaks down.
STRIDE sorts threats into six categories, each the mirror of a security property it breaks. It finds threats thoroughly but does not rank them.
The five phases of the BCP lifecycle, how BCP differs from DRP, who is accountable for the programme, and the six testing methods in order of disruption.
How a business impact analysis finds critical functions, measures impact over time, maps dependencies, and produces the recovery priorities strategy must meet.
Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both.
Scoping makes binary yes or no calls on whether a control applies. Tailoring customises how it is implemented. A CISSP insight with a manager mindset.
Separation of duties splits a workflow across people and stages. Dual control makes two people act together on one action. The difference is when they act.
The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis.
The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis.
The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.
The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.
The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.
The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once.
An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.
The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.
Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part.
The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.
The binary decision about whether a baseline control applies to your environment at all. A control for a technology you do not run is scoped out. Applicability, not customisation.
Customising how the controls that apply to your environment are implemented: adjusting parameters, adding compensating controls, or refining assumptions to fit organisational reality.
Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production.
Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property.
Microsoft's threat-scoring model: Damage, Reproducibility, Exploitability, Affected users, Discoverability, rated on an agreed scale to rank threats a framework such as STRIDE has already found.
Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.
The organisation-wide plan for keeping critical business functions running during and after a disruption. The umbrella programme that disaster recovery sits underneath.
The process that identifies critical business functions and the impact of their disruption over time, producing the recovery metrics (RTO, RPO, MTD) that drive continuity planning.
Splitting a critical process across multiple people so no individual can complete it alone, forcing collusion to commit fraud. A core control in Clark-Wilson and Domain 1 alike.
A control that requires two or more people to act together, at the same moment, to complete a single sensitive operation, so that no individual can perform it alone.
Layering physical, technical, and administrative controls so no single control failure exposes an asset; every layer assumes the layer in front of it can be breached.
Reading is half of it. Scenario questions in this domain tend to turn on the distinctions above, and the quickest way to find out which ones you hold is to answer some. The CISSP practice tests cover all eight domains with an explanation for every answer, and the free assessment gives you a baseline first.