From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Quantitative risk assessment

Quantitative risk assessment

- [Instructor] When we're able to gather quantitative data about our assets and risks, we can use that information to make data-informed decisions about risk. The process of using numeric data to assist in risk decisions is known as quantitative risk management. Security professionals performing a quantitative risk assessment do so for a single risk asset pairing at a time. For example, they might conduct an assessment based upon the risk of flooding to a data center. As they conduct the assessment, they must first determine the values for several variables. The first of these is the asset value or AV. This is quite simply the estimated value in dollars of that asset. Risk assessors determining an asset's value have several options available to them. The original cost technique simply looks at the invoices from an asset purchase and uses those purchase prices to determine the asset value. This is the easiest technique to perform because it simply requires looking at those invoices…

Contents