Risk identification, assessment and analysis
Objective 5.2 in this course covers the risk management process — CompTIA's scope note for it explains risk identification, assessment, analysis, register, tolerance, appetite, strategies, reporting and business impact analysis. This lesson takes identification through analysis, including the arithmetic; the register, appetite, strategies and BIA are the next lesson.
Why this matters
This is the objective with calculations in it. SLE, ALE and ARO are the only arithmetic on SY0-701, they are simple, and they are reliably asked — which makes them among the most efficient marks on the whole exam.
It is also where the vocabulary must be exact. Threat, vulnerability, risk and impact are four different things, and the exam offers all four as options to a question about one of them.
The lesson
Risk identification, and the register it feeds
Start with the definitions, precisely:
- A threat is something that could cause harm — a ransomware group, a fire, a careless employee, a failing disk.
- A vulnerability is a weakness that a threat could exploit — an unpatched service, no backups, excessive permissions.
- Risk is the combination: the likelihood that a threat exploits a vulnerability, and the impact if it does. No vulnerability, no risk — a threat with nothing to exploit is not a risk, and that is a distinction the exam tests.
- Impact is the consequence if it happens.
- Likelihood or probability is how often it is expected to.
Risk identification is finding them, and the sources are deliberately varied, because each finds a different kind:
- vulnerability scans and penetration tests (technical);
- audits and assessments (process and compliance);
- incidents and near-misses, yours and other organisations';
- threat intelligence (what is actually happening to people like you);
- business change — a new product, market, supplier or acquisition;
- and asking people, which finds the risks nobody has instrumented for.
Every identified risk goes into the risk register, which is the subject of the next lesson. The register is the point of identification; a risk that is found and not recorded has not been managed, it has been noticed.
A framing worth carrying: express risks as a sentence with a cause and a consequence. "Ransomware" is not a risk statement. "An employee opens a malicious attachment, malware encrypts the file servers, and we cannot trade for five days" is one — it names what happens, and it can be assessed.
Ad hoc, recurring, one-time and continuous assessment
Risk assessment is evaluating identified risks. CompTIA names four cadences, and the exam matches them to circumstances:
- Ad hoc — triggered by an event: a new threat, an incident, a sudden change. Responsive and unplanned.
- Recurring — on a schedule, quarterly or annually. Ensures nothing is forgotten, and is what auditors expect to see evidence of.
- One-time — for a specific purpose, such as evaluating a particular acquisition, project or new system.
- Continuous — ongoing, automated, always current. The direction of travel, enabled by the automated scanning and monitoring from Domain 4.
A mature programme uses all four: continuous where automation allows, recurring for the whole picture, one-time for projects, ad hoc for events.
Assessments are also either qualitative or quantitative, which is the next section, and either internal or external — where external brings independence and a view of how others do it, at a cost.
Qualitative and quantitative analysis, and when each is honest
Qualitative analysis uses descriptive ratings: high/medium/low, or a 1–5 scale for likelihood and impact, combined in a risk matrix. It is fast, works where no data exists, and communicates well to non-specialists.
Its weakness is that the numbers are not really numbers. Two "high" risks may differ by three orders of magnitude in cost, and a matrix cannot tell you whether a control is worth its price.
Quantitative analysis puts money on it, using the formulas below. It supports genuine cost-benefit decisions and it requires data — asset values, frequency estimates — that organisations often do not have.
The honest position, and the one the exam supports: quantitative where you have data, qualitative where you do not, and never pretend qualitative output is quantitative. The characteristic failure is a five-by-five matrix whose cells are multiplied together to give a "risk score" of 16, which is then treated as a measurement. It is an ordinal rating dressed as arithmetic, and it will rank two incomparable things confidently.
SLE, ALE, ARO and the arithmetic the exam will make you do
The formulas. Learn these exactly.
- AV (asset value) — what the asset is worth.
- EF (exposure factor) — the proportion of the asset lost in a single incident, as a percentage or decimal.
- SLE (single loss expectancy) = AV × EF. The cost of one occurrence.
- ARO (annualised rate of occurrence) — how many times per year it is expected. Once every four years is 0.25.
- ALE (annualised loss expectancy) = SLE × ARO. The expected cost per year.
A worked example of the shape the exam uses:
A server is valued at £80,000. A flood would destroy 60% of its value. Floods in this location occur once every 20 years. What is the ALE?
- SLE = 80,000 × 0.6 = £48,000
- ARO = 1 / 20 = 0.05
- ALE = 48,000 × 0.05 = £2,400
The point of ALE is the decision it enables. A control costing £10,000 a year to mitigate a £2,400 ALE is not worth it on those numbers alone. A control costing £500 a year clearly is. The comparison is ALE before minus ALE after, against the annual cost of the control — and the difference is sometimes called the cost-benefit or the value of the safeguard.
Two cautions the exam rewards:
- ALE is an average, not a prediction. An ARO of 0.05 does not mean a small loss every year; it means nothing for nineteen years and £48,000 once. For a risk that could end the organisation, the average is the wrong basis for the decision, because you cannot survive the single event by pointing at the mean.
- Some impacts do not convert to money honestly — loss of life, regulatory licence, reputational collapse. Forcing them into a currency figure produces a confident wrong answer, and those risks are managed on their consequence rather than their expected value.
Watch the units in exam questions: "once every four years" is 0.25, "twice a year" is 2, and "60%" is 0.6. Most lost marks here are arithmetic slips on the ARO, not conceptual errors.
Probability, likelihood, exposure factor and impact
Finishing the vocabulary, because the exam distinguishes terms people treat as synonyms.
- Probability is a mathematical measure — a number between 0 and 1, derived from data. Appropriate where you have the data: hardware failure rates, historical incident counts.
- Likelihood is broader and usually qualitative — a judgement expressed as rare/unlikely/possible/likely/almost certain. Used where the data does not exist, which is most security risks, because attacker behaviour is not a stationary statistical process.
- Exposure factor is the proportion of an asset lost in one event, not the chance of it happening. It is the term most often confused, and the confusion is testable: EF is about severity, ARO is about frequency.
- Impact is the consequence, and it has several dimensions that should be assessed separately: financial, operational, reputational, regulatory, and — for some organisations — safety.
The assembling idea: risk = likelihood × impact, in whatever units you are working in. Everything above is a way of being more precise about one of those two factors.
And the distinction that closes the lesson and opens the next one: inherent risk is the risk before controls, residual risk is what remains after them, and control risk is the risk that the controls themselves fail. Residual risk is what gets accepted, by the person governance authorised to accept it — which is where the next lesson begins.
What to take into the exam
- Threat + vulnerability = risk. A threat with nothing to exploit is not a risk.
- SLE = AV × EF. ALE = SLE × ARO. "Once every N years" gives ARO = 1/N.
- Compare the reduction in ALE against the annual cost of the control.
- ALE is an average and is the wrong basis for a risk that could end the organisation.
- Exposure factor is severity (how much of the asset), ARO is frequency (how often).
- Inherent risk is before controls, residual is after, and residual is what gets accepted.
Practise what you just read
1. An asset worth 80,000 has an exposure factor of 0.5 and an ARO of 0.25. What is the ALE?
Select one
Show answer
A. SLE is 80,000 x 0.5 = 40,000. ALE is SLE x ARO = 40,000 x 0.25 = 10,000. Most lost marks here are unit slips on the ARO: 'once every four years' is 0.25, not 4.
2. A threat exists but there is no corresponding weakness. What is the risk?
Select one
Show answer
A. Risk is the combination of a threat exploiting a vulnerability and the impact if it does. A threat with nothing to exploit is not a risk, and that distinction is tested directly because the four terms are used interchangeably in ordinary speech.
3. Which assessment cadence is triggered by an event rather than a schedule?
Select one
Show answer
A. Ad hoc is responsive: a new threat, an incident, a sudden change. Recurring is scheduled and is what auditors expect evidence of, one-time is project-specific, and continuous is automated and always current.
9 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA Security+ SY0-701 course — 47 lessons and 79 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-701 and is not produced by or endorsed by CompTIA.