Summary of Formulas


Use

Description

Formula

Definition of risk

Used to represent risk

Risk = asset value × threat × vulnerability

Threat calculation

Numeric representation of threat

Threat = exposure factor (EF) × annual rate of occurrence (ARO)

Vulnerability calculation

Measures control deficiency

Control deficiency (CD) = 1 - control effectiveness

Risk calculation

Used to quantify risk

Risk = asset value × EF × ARO × CD



IT Auditing. Using Controls to Protect Information Assets
It Auditing: Using Controls to Protect Information Assets [IT AUDITING -OS N/D]
ISBN: B001TI1HNG
EAN: N/A
Year: 2004
Pages: 159

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net