EF
Exposure factors
• What it is: The percentage of loss a system or asset would suffer if a threat happens.
• Purpose: Helps calculate how much risk an incident could cause.
✅ Example:
• A server is worth $100,000.
• A fire could destroy 40% of its value.
• Exposure Factor = 40% → potential loss = $40,000.
SLE
Single Loss Expectancy (SLE)
• What it is: The expected monetary loss if a single security incident happens.
• Formula:
\text{SLE} = \text{Asset Value (AV)} \times \text{Exposure Factor (EF)}
✅ Example:
• Asset Value (server) = $100,000
• Exposure Factor = 40% (if hit by a threat)
• SLE = $100,000 × 0.4 = $40,000
• This means one incident could cost $40,000.