How soon do you need this? I have the first cypher done. (I like the quote, BTW)
The last question is going to take me some time to research.
The formula I have needs a value for "exposure factor." Is that computed from the information given? If so, do you have a better formula that I can use?
How can I see the answers? This is due by tomorrow midnight.
Is this ok?
ARO: Annual Rate of Occurrence – the number of times in a given year that an event is expected to
occur. This can be expressed as a fraction (such as 1 in 15, 1 in 200, 1 in X, etc.) meaning that the
event is expected to occur at least once (1) in some number of years (X).
ALE: Annual Loss Exposure (aka risk exposure) – the expected annual loss due to an event. This is
typically expressed as a dollar amount.
You work for a company whose offices are flooded. All of the servers in the corporate data center
on site are ruined. The total cost of all the systems was $500,000. The offices happened to be in a
100-year flood plain (the ARO for a massive flood in a given year was 1 in 100). Calculate the ALE
for this event.
In this case the ARO is already given: 1 in 100 = .01
The cost of the systems is $500,000.
So, the ALE is the cost of the systems multiplied by the ARO or:
$500,000 x .01 = $5000
Now, this is NOT the cost of the loss. This is the annual risk exposure that a massive flood would
take out the systems. The cost of the loss, if a 100-year flood occurs is $500,000. This is just a way
to give IT and security managers a way to figure out whether they need to install a control that
would mitigate this problem.
Your company pays an annual maintenance fee of $1000 to an anti-virus company, MyAV.com, to
stay current on the anti-virus software. One day, an employee receives an e-mail with a new virus
attached and opens the e-mail. Every mailbox in the company directory is infected. It will take
the IT staff 3 days to clean all of the affected mailboxes at a cost of approximately $10,000. The
chance of this happening, according to MyAV.com’s account manager, was 1 in 20. In addition,
the cost of loss of sales opportunity amounts to an additional $25,000. Calculate the ALE.
In this case the total loss is the loss of sales opportunities as well as the cost of the cleanup:
$10,000 + $25,000 = $35,000.
MyAV.com claims that the ARO was 1 in 1000 or .05
Therefore the ALE is: $35,000 x .05 = $1,750
The account manager for another anti-virus company, YourAV.com, contacts you after he hears
about your virus infection. He claims that his product, YourAV, would perform better than the
competitor, MyAV, and that such an event with his product would only have a 1 in 200 chance of
occurring. He offers you a competitive “upgrade” to his product for $500.00. Calculate the ALE
and the risk leverage.
The loss in this case would still be $35,000. But now, the ARO is .005. So, the ALE is:
$35,000 x .005 = $175.00
The risk leverage is:
[ ($1,750) – ($175) ] / $500 = 3.15 (a relatively low number and so the solution is worthwhile
Can I get it by tomorrow morning! It is due by tomorrow night( final deadline).
No problems. Your post said high urgency, so I was afraid it was due very soon.
Ok and thanks! Just want to put it together with other questions when I receive them. How is it going by the way?
I have double and triple checked the numbers. I am quite happy with them, but please check it again. I told you that I am not familiar to this topic.
OH! Hold on. Cancel that. I need to fix them!
I suddenly remembered that the loss was 12 hours instead of 24.
Still cannot download the questions!
Ok, let me try wikisend.
Yes, please convert it into a word document so that I can copy and paste in my home curate?which is a word document as well. Can you also ensure that the risk answer is demonstrated with steps and ac
Thanks! I justed dowloaded it and will let you know. I also submitted new questions and can you look them? I will complette the survey as well!
Ok, they are information assuarance and networking! How do you feel for the previous answers? Do the affine has to align( rows)?
The affine is just in rows to show how it works. C (number 2) goes to O (number 2*3+8=14) whether it is in rows or not.