Safeguard Cost/Benefit Analysis The risk assessment is now almost complete, though this final set of calculations is, once again, not trivial. In previous steps, the expected value of risk mitigation the Annualized Loss Expectancy (ALE) is conservatively represented individually, safeguard by safeguard, and collectively. The collective safeguard cost/benefit is represented first, threat by threat with applicable selected safeguards; and, second, showing the overall integrated risk for all threats with all selected safeguards applied. This may be illustrated as follows: Safeguard1 --> Vulnerability1-->n --> Threat1-->n One safeguard may mitigate one or more vulnerabilities to one or more threats. A generalization of each of the three levels of calculation is represented below:
where: This information is useful in determining whether individual safeguards are cost effective. If the net risk reduction benefit is negative, the benefit is negative, i.e., not cost effective. [(AALEB - AALEA = GRRB) -SGAACSG1-n] = NRRB
where: In this case, NRRB refers to the combined benefit of the collective population of safeguards selected for a specific threat. This process should be executed for each threat addressed. Still, these two processes alone should not be regarded as definitive decision support information. There remains the very real condition that the collective population of safeguards could reduce risk very effectively for one major threat while having only a minor risk-reducing effect for a number of other threats relative to their collective SGAAC. In other words, if looked at out of context, the selected safeguards could appear, for those marginally affected risks, to be cost prohibitive their costs may exceed their benefit for those threats. Therefore, the next process is essential to an objective assessment of the selected safeguards overall benefits.
|
We are proud to bring to all of our members a legal copy of this outstanding book. Of course this version is getting a bit old and may not contain all of the info that the latest version are covering, however it is one of the best tool you have to review the basics of security. Investing in the latest version would help you out in your studies and also show your appreciation to Auerbach for letting me use their book on the site.