首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario applies to questions 27 and 28. Sam is the security manager of a company that makes most of its revenue f
The following scenario applies to questions 27 and 28. Sam is the security manager of a company that makes most of its revenue f
admin
2013-12-19
96
问题
The following scenario applies to questions 27 and 28.
Sam is the security manager of a company that makes most of its revenue from its intellectual property. Sam has implemented a process improvement program that has been certified by an outside entity. His company received a Level 2 during an appraisal process, and he is putting in steps to increase this to a Level 3. A year ago when Sam carried out a risk analysis, he determined that the company was at too much of a risk when it came to potentially losing trade secrets. The countermeasure his team implemented reduced this risk, and Sam determined that the annualized loss expectancy of the risk of a trade secret being stolen once in a hundred-year period is now $400.
What is the associated single loss expectancy value in this scenario?
选项
A、$65,000
B、$400,000
C、40000
D、4000
答案
D
解析
C正确。计算年度损失期望值(ALE)的公式为单一损失期望(SLE)×年度发生率(ARO)=ALE。在这个情景中,如果ALE是$400且ARO为0.01,则SLE为$40 000。
A不正确。因为得到SLE的公式为资产价值×曝光因子=SLE,而ALE是单一损失期望(SLE)×年度发生率(ARO)=ALE。如果某个交易秘密在一百年的时间内被偷一次的风险的ALE为$400,则你只能反向计算得到SLE的值。如果ALE是$400,ARO为0.01,则得到的SLE值为$40 000。
B不正确。因为得到SLE的公式为资产价值×曝光因子=SLE,而ALE是单一损失期望×年度发生率(ARO)=ALE。在这个场景中,某个交易秘密在一百年的时间内被偷一次的风险的ALE为$400,如果ALE是$400,ARO为0.01,则得到的SLE值为$40 000。
D不正确。因为得到SLE的公式为资产价值×曝光因子=SLE,而ALE是单一损失期望×年度发生率(ARO)=ALE。完成这些计算的目的是为了全面理解特定风险的急迫性,并了解实施一种成本有效的对策可以花费多少。
转载请注明原文地址:https://kaotiyun.com/show/UNhZ777K
0
CISSP认证
相关试题推荐
Salt,shellsormetalsarestillusedasmoneyinout-the-waypartsoftheworldtoday.Saltmayseemratherastrange【C1】__
ThefamilyisthecenterofmosttraditionalAsians’lives.Manypeopleworryabouttheirfamilieswelfare,reputation,andhono
Themainpurposeofaresumeistoconvinceanemployertograntyouaninterview.Therearetwokinds.Oneisthefamiliar"tom
Nano-sizedtoothbrushesthatcancleanverysmallsurfaceshavebeendevelopedbyresearchers.Fabricatedoutofmillionsofcar
Inthe1930s,anAmericanmeatcompanycameoutwithaspicedhamproductsoldinacan.Beforelong,Spam,asitwascalled,be
[A]Meetingdifferentneeds[B]Smallerisbetter[C]Betterproductmakesgreaterquantity[D]Qualityvsquantity[E]Chillyc
In1930,whentheworldwas"sufferingfromabadattackofeconomicpessimism",JohnMay-nardKeyneswroteabroadlyoptimisti
Writeanessayof160-200wordsbasedonthefollowingdrawings.Inyouressay,youshould1)describethedrawingsbriefly,
Howmenfirstlearnedtoinventwordsisunknown;inotherwords,theoriginoflanguageisamystery.Allwereallyknowistha
Advertisingwasjustonebusinessmodelthatpeopleconsideredatthestart.Googleoriginallythoughtmaybe15percentofthe
随机试题
我过去常常浪费很多时间玩游戏。
19世纪三四十年代,欧洲无产阶级已经觉醒。“觉醒”是指()
A.发热伴胸痛B.发热伴明显的肌肉痛C.发热伴黄疸D.发热伴淋巴结无痛性肿大E.发热伴4天后出皮疹淋巴瘤常为
阻碍骨折愈合的治疗方法为()
A、毒性噬菌体B、温和噬菌体C、溶原性细菌D、前噬菌体E、L型细菌使相应细菌裂解的噬菌体称为
吸收客户资金不入账罪,是指银行或者其他金融机构的工作人员,吸收客户资金不入账的行为。()
下列关于甲烷的说法错误的是()。
根据《合同法》和《担保法》的有关规定,下列表述正确的是()。
某公司欲开发一个电子交易清算系统,在架构设计阶段,公司的架构师识别出3个核心质量属性场景。其中“数据传递时延不大于1s,并提供相应的优先级管理”主要与(58)________质量属性相关,通常可采用(59)________架构策略实现该属性:“系统采用双
WhatmadeonefirmofpublishersrefusetoacceptDominic’sfirstbook?
最新回复
(
0
)