A Chief Information Security Officer (CISO) is conducting a quantitative risk assessment for a legacy customer database server with an estimated Asset Value () of . Threat metrics indicate an Annual Rate of Occurrence () of for unauthorized data extraction attacks. Without additional security controls, the Exposure Factor () for a successful compromise is .
To mitigate this risk, the organization evaluates deploying an Endpoint Detection and Response (EDR) solution combined with network microsegmentation. This countermeasure costs annually to license and manage, and it reduces the Exposure Factor () to while leaving the unchanged.
What is the net annual cost benefit of implementing this countermeasure?
- Answer
- B
- C
- D
Answer
The net annual cost benefit of implementing the safeguard is .
To calculate net annual cost benefit, compare the baseline annualized risk () with post-mitigation annualized risk () and control operational expenditure:
1.
2.
3.
4.
5. Net Benefit = .
Thus, implementing the countermeasure yields a net annual financial benefit of .
1.
2.
3.
4.
5. Net Benefit = .
Thus, implementing the countermeasure yields a net annual financial benefit of .
Step-by-Step Solution
Key Concept
Quantitative Risk Assessment and Cost-Benefit Analysis ()