CAS-003 · Question #447
A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with…
The correct answer is A. ALE D. ARO. ROI for a security control is calculated by comparing the cost of the control against the Annual Loss Expectancy (ALE). ALE is derived from multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO), making both values required inputs.
Question
A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with mitigation. Middleware for mitigation will cost $100,000 per year. Which of the following must be calculated to determine ROI? (Choose two.)
Options
- AALE
- BRTO
- CMTBF
- DARO
- ERPO
How the community answered
(37 responses)- A78% (29)
- B14% (5)
- C3% (1)
- E5% (2)
Why each option
ROI for a security control is calculated by comparing the cost of the control against the Annual Loss Expectancy (ALE). ALE is derived from multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO), making both values required inputs.
ALE (Annual Loss Expectancy) represents the expected yearly financial loss from a risk, calculated as SLE x ARO. Comparing the $100,000 annual middleware cost against the ALE determines whether the investment is justified and yields a positive ROI.
RTO (Recovery Time Objective) defines the maximum tolerable downtime for a system; it is a business continuity metric, not a financial risk calculation input.
MTBF (Mean Time Between Failures) measures hardware reliability and availability; it informs maintenance decisions but is not a direct input to the ALE-based ROI formula.
ARO (Annualized Rate of Occurrence) quantifies how often a threat is expected to occur per year. Without ARO, ALE cannot be calculated, making it a required component of the ROI determination.
RPO (Recovery Point Objective) defines the acceptable amount of data loss measured in time; it is a business continuity metric unrelated to the financial ROI calculation for a security control.
Concept tested: Calculating security control ROI using ALE and ARO
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.