Cyber Intelligence
Security Program Management & Oversight · 20% of exam

L17. Risk Management: Frameworks, Assessment & Treatment

Course outlineLesson 17 of 20

Risk management is the systematic process of identifying, assessing, and responding to threats to an organization's assets. The Security+ exam tests both the conceptual models and the quantitative calculations.

Risk Fundamentals

Risk = Likelihood × Impact

A vulnerability with low likelihood or low impact may not warrant expensive controls. Risk management is about prioritizing finite security resources against the most significant threats. Threat: a potential event that could harm an asset (e.g., ransomware attack) Vulnerability: a weakness that a threat can exploit (e.g., unpatched server) Risk: the combination of threat likelihood and potential impact Residual risk: the risk remaining after controls are applied

Quantitative Risk Analysis

Quantitative analysis uses financial figures to express risk:

  • SLE (Single Loss Expectancy): asset value × exposure factor. The financial loss from a single incident.
  • ARO (Annual Rate of Occurrence): how many times the incident is expected per year.
  • ALE (Annual Loss Expectancy): SLE × ARO. The expected annual financial loss.

Example: Server worth $100,000. Exposure factor 40% (40% of server value lost per incident). SLE = $40,000. Expected 0.5 incidents/year. ALE = $20,000/year. A control costing less than $20,000/year is worth implementing.

Risk Treatment Options

OptionDescriptionExample
AcceptTolerate the residual risk; document the decisionAccept low-severity vulnerability on isolated system
AvoidStop the activity that creates the riskStop offering a high-risk service
TransferShift financial consequences to a third partyCyber insurance, SLA with vendor
MitigateImplement controls to reduce likelihood or impactPatch the vulnerability, add MFA
Note: You can never fully eliminate risk. The goal is to reduce it to an acceptable level.

NIST Risk Management Framework (RMF)

NIST SP 800-37 defines a 6-step RMF:

  1. Categorize system based on impact to CIA
  2. Select baseline security controls (from NIST SP 800-53)
  3. Implement selected controls
  4. Assess controls to verify they are implemented correctly and effective
  5. Authorize the system (ATO: Authority to Operate)
  6. Monitor controls continuously
Exam Focus Points
  • Risk = Likelihood × Impact; residual risk is what remains after controls are applied
  • ALE = SLE × ARO: the expected annual financial loss from a specific threat (used in quantitative risk analysis)
  • Risk treatment: Accept (tolerate), Avoid (stop the activity), Transfer (insurance), Mitigate (add controls)
  • NIST RMF 6 steps: Categorize, Select, Implement, Assess, Authorize (ATO), Monitor
  • Risk can be reduced but never fully eliminated; the goal is to reduce it to an acceptable residual level
Knowledge Check

1. An organization calculates that a data breach would cost $500,000 (SLE) and expects one breach every 5 years (ARO = 0.2). What is the ALE?

2. A company stops offering a high-risk online payment feature because the security controls required to protect it would cost more than the revenue it generates. Which risk treatment strategy is this?

3. Which step of the NIST RMF grants formal approval for a system to operate based on the determined risk posture?

Recommended: Pluralsight

Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.

Start Security+ prep free10-day free trial available