Calculate ARO, ALE, and CBA
Learning Objective: Use existing conceptual frameworks to evaluate risk controls, and formulate a cost-benefit analysis.
One year ago, the Mesusa Corporation conducted a threat evaluation and created a list of threats, the cost per incident and the projected frequency of occurrence. During the year, Mesusa decided to implement controls designed to reduce the cost per incidence and the number of threats. The spreadsheet, MesusaControls.xls, indicates thepre-control cost and frequency of occurrence, the cost of controls for each type of threat, and the post-control cost and frequency of occurrence. Calculate the AROs, theALEs and the CBA for this initiative, and return the completed spreadsheet. You can use the websites linked above to help you out. Please include your name on your spreadsheet before submission.
NOTE: The spreadsheet will be provided to you from the professor at the beginning of the week.
- Format: Microsoft Excel
- Font: Arial, 12-Point
Textbook: Management of Information Security, 4th ed