The following is an example of how to perform a qualitative risk assessment. You can use this example in your own organization by replacing the values in the book with your own:
- First determine your threat, vulnerability, and risk:
- Threat: Loss of customer information
- Vulnerability: Web application vulnerabilities
- Risk: Loss of information
- Determine the Asset Value (AV):
- AV = $200,000.00
- You should work with your business units when developing the assets value. The loss of data will mean something different to an IT user, a business user, and information security user.
- Determine the Exposure Factor (EF):
- EF = 1.0
- 100% = 1.0
- In this case, the organization determined that a loss of this information ...