A large enterprise is implementing a new risk assessment process. The CISO requires a methodology that produces objective metrics that can be compared across different business units and tracked over time. Which of the following risk assessment approaches would BEST meet these requirements?
The correct answer is Quantitative risk assessment. Quantitative risk assessment methodologies provide objective metrics through the use of numerical data and mathematical calculations to evaluate risk. This approach allows for consistent measurement across different business units and meaningful comparisons over time because it relies on concrete values rather than subjective judgments.
Quantitative assessments typically involve calculations such as Annual Loss Expectancy (ALE), Single Loss Expectancy (SLE), and Return on Security Investment (ROSI). These metrics enable organizations to prioritize risks based on measurable impact and probability values.
Qualitative risk assessment uses subjective ratings (like high, medium, low) based on expert judgment rather than concrete metrics, making consistent comparison difficult across business units. Hybrid risk assessment combines elements of both but wouldn't fully satisfy the requirement for objective metrics. Residual risk assessment focuses on evaluating the risk that remains after security controls are implemented, not specifically on providing comparable metrics.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Annual Loss Expectancy (ALE) and how is it calculated?
Open an interactive chat with Bash
What are the advantages of using quantitative risk assessment over qualitative methods?
Open an interactive chat with Bash
What is the difference between qualitative and quantitative risk assessment?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access