preview

Nt1330 Unit 7 Exercise 1

Decent Essays

Quantitative risk analysis involves steps, calculations and tools to have a good analysis. The steps involve with this method from (wikibooks n.d) includes: assigning value to assets, Estimating potential loss per threat, Performing a threat analysis and Deriving the overall loss potential per threat. Firstly, in order to assign an accurate value to an asset, all tangible and intangible assets must be identified. For instance a company may have a server and to determine the value of the server, the important of the server to the company and the cost of losing server are factors that helps in determining the value for the server. Secondly, the potential loss per threat should be estimated. If a server is hacked, how much loss will it cost to the company? To know that, the Single Loss Expectancy (SLE) has to be calculated. SLE is the asset value (AV) times the exposure factor (EF). Thirdly, risk analysis have to be performed. In the case of a server being stolen, it has to be determine how many times in a year can it happen. To know this, the Annual Rate of Occurrence (ARO) have to be calculated. Also, the overall loss potential per threat have to be known. The overall loss that can be incur from a stolen server and the probability that a server will be stolen can be derived by calculating the Annual Lost Expectancy (ALE) which is annual rate of …show more content…

Technical controls involves the use of technology and expertise to mitigate risk. An administrator who installs and configures a firewall and IDS to prevent attacks on the network is implementing a technical security control. Management controls use planning and assessment ways to reduce risk. Conducing risk assessment, vulnerability assessment and penetration testing. Lastly. Operational controls are implement by people. Having awareness training and having a contingency plan is a way of implementing operation controls (Darril

Get Access