← All Cheat Sheets

Risk Management Formulas

Key risk calculations, metrics, and decision criteria.

Risk Management Formulas

Essential risk calculations and decision criteria for the CISA exam. Memorize these formulas and understand when to apply each one.

Core Risk Formulas

Formula Calculation Purpose
RiskThreat x Vulnerability x ImpactQualitative risk assessment
SLEAsset Value x Exposure Factor (EF)Loss from a single incident
ALESLE x Annualized Rate of Occurrence (ARO)Expected yearly loss
Residual RiskInherent Risk - Control EffectivenessRisk remaining after controls
Cost-BenefitALE (before) - ALE (after) - Control CostJustify control investment

Worked Example

Scenario: A server worth $200,000 faces a threat that would destroy 40% of its value. The event is expected to occur once every 5 years.

  • EF = 40% (0.4)
  • SLE = $200,000 x 0.4 = $80,000
  • ARO = 1/5 = 0.2
  • ALE = $80,000 x 0.2 = $16,000/year

A control costing less than $16,000/year is justified if it eliminates the risk entirely.

Risk Response Options

Response Action Example
MitigateImplement controls to reduce riskInstall firewall, encrypt data
TransferShift risk to a third partyPurchase cyber insurance
AcceptAcknowledge and absorb the riskRisk is below tolerance threshold
AvoidEliminate the activity causing riskDiscontinue a risky service

Key Terms

  • Inherent Risk: Risk before any controls are applied
  • Control Risk: Risk that a control fails to prevent or detect an issue
  • Detection Risk: Risk that the auditor fails to detect a material error
  • Risk Appetite: The amount of risk an organization is willing to accept
  • Risk Tolerance: The acceptable variation from the risk appetite

Ready to test your knowledge?

Put this cheat sheet to work with scenario-based CISA practice questions.

Start Free