What is a qualitative risk assessment?
A qualitative risk assessment evaluates individual risk factors and their criteria.
How can a qualitative risk assessment be displayed?
In broad terms, often using a traffic light grid to show low, medium, or high risk.
What might be the overall risk level for legacy Windows clients with medium-level impact and high annualized rate of occurrence?
High.
What is the Annualized Rate of Occurrence abbreviated as?
ARO.
What does Asset Value (AV) represent?
The value of an asset to the organization, including effects on sales and potential fines.
What does the Exposure Factor (EF) measure?
The percentage of the asset value lost due to a specific risk.
What is Single-Loss Expectancy (SLE)?
The monetary loss expected from a single event occurring.
How is SLE calculated?
By multiplying the Asset Value (AV) by the Exposure Factor (EF).
What does Annualized Loss Expectancy (ALE) represent?
The total expected loss in a year from a specific risk.
How is ALE calculated?
By multiplying the Annualized Rate of Occurrence (ARO) by the Single-Loss Expectancy (SLE).
What is the highest priority concern in risk calculations?
Life.
What is the difference between risk likelihood and risk probability?
Likelihood is qualitative; probability is quantitative.
What is risk appetite?
The amount of risk an organization is willing to take.
What does risk tolerance refer to?
The larger variance of acceptable risk compared to risk appetite.
Fill in the blank: The register that documents risks associated with a project is called a ______.
risk register.
What is the purpose of a risk register?
To document individual risks and provide options to avoid them.
What is a key risk indicator?
An indicator that details potential risks in a project.
What should be assigned to each key risk indicator in a risk register?
An owner responsible for managing that particular risk.
What needs to be balanced when resolving risks in a project?
The cost of resolving the risk and the potential cost of the risk to the company.
True or False: A risk appetite posture can be classified as conservative, neutral, or expansionary.
True.