A chief information security officer (CISO) is reviewing the quantitative risk assessment report for an organization's legacy data center hosting critical data storage arrays. The assessment establishes an Asset Value () of , an Exposure Factor () of , and an Annual Rate of Occurrence () of . The risk management team is evaluating several potential risk handling options. Which of the following statements accurately describe the risk metrics and response strategies in this scenario? (Select TWO.)
- Purchasing a targeted cyber insurance policy to offset potential financial losses from server downtime constitutes a risk transference strategy.Answer
- The unmitigated Annual Loss Expectancy () prior to implementing additional safeguards is .Answer
- CDecommissioning the legacy equipment and ceasing the associated high-risk operational process represents a risk mitigation control.
- DThe Single Loss Expectancy () for a single occurrence is , calculated by dividing the Asset Value by the Annual Rate of Occurrence.
Answer
The correct statements are that purchasing a cyber insurance policy constitutes risk transference, and that the unmitigated Annual Loss Expectancy () is .
Purchasing insurance is a textbook example of risk transference because financial risk is shifted to a third party. Furthermore, calculating the annualized financial exposure yields an of (; ).
Step-by-Step Solution
Key Concept
Quantitative risk analysis metrics (, ) and standard risk response strategies (transference vs. avoidance vs. mitigation).