Risk Management Formulas
Essential risk calculations and decision criteria for the CISA exam. Memorize these formulas and understand when to apply each one.
Core Risk Formulas
| Formula | Calculation | Purpose |
|---|---|---|
| Risk | Threat x Vulnerability x Impact | Qualitative risk assessment |
| SLE | Asset Value x Exposure Factor (EF) | Loss from a single incident |
| ALE | SLE x Annualized Rate of Occurrence (ARO) | Expected yearly loss |
| Residual Risk | Inherent Risk - Control Effectiveness | Risk remaining after controls |
| Cost-Benefit | ALE (before) - ALE (after) - Control Cost | Justify control investment |
Worked Example
Scenario: A server worth $200,000 faces a threat that would destroy 40% of its value. The event is expected to occur once every 5 years.
- EF = 40% (0.4)
- SLE = $200,000 x 0.4 = $80,000
- ARO = 1/5 = 0.2
- ALE = $80,000 x 0.2 = $16,000/year
A control costing less than $16,000/year is justified if it eliminates the risk entirely.
Risk Response Options
| Response | Action | Example |
|---|---|---|
| Mitigate | Implement controls to reduce risk | Install firewall, encrypt data |
| Transfer | Shift risk to a third party | Purchase cyber insurance |
| Accept | Acknowledge and absorb the risk | Risk is below tolerance threshold |
| Avoid | Eliminate the activity causing risk | Discontinue a risky service |
Key Terms
- Inherent Risk: Risk before any controls are applied
- Control Risk: Risk that a control fails to prevent or detect an issue
- Detection Risk: Risk that the auditor fails to detect a material error
- Risk Appetite: The amount of risk an organization is willing to accept
- Risk Tolerance: The acceptable variation from the risk appetite
Ready to test your knowledge?
Put this cheat sheet to work with scenario-based CISA practice questions.
Start Free