CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A Chief Information Security Officer (CISO) is presenting the organization's cybersecurity posture to the board of directors. The board is primarily interested in the financial risks associated with cyber threats and the potential return on investment (ROI) for new security initiatives. Which risk assessment approach should the CISO use to best communicate these financial implications?

  1. AQualitative Risk Assessment
  2. BScenario-Based Risk Assessment
  3. CQuantitative Risk Assessment
  4. DHybrid Risk Assessment
Show answer & explanation

Correct answer: C. Quantitative Risk Assessment

Quantitative risk assessment focuses on assigning monetary values to assets, threats, and vulnerabilities to calculate potential financial losses (e.g., SLE, ALE). This approach provides concrete financial figures that are directly relevant to a board of directors interested in financial risks and ROI.

Why the other options are wrong

  • A. Qualitative risk assessment uses descriptive terms (e.g., high, medium, low) and is less effective for communicating financial ROI to a board.
  • B. Scenario-based risk assessment explores specific situations but may not directly provide the overall financial impact and ROI needed by the board.
  • D. Hybrid risk assessment combines both, but for direct financial communication, the quantitative aspect is key, and this option is less precise than 'Quantitative'.

Quantitative Risk Assessment

An objective, numerical approach to risk assessment that assigns monetary values to assets, threats, and vulnerabilities.

  • Calculates potential financial loss (SLE, ALE).
  • Provides data for cost-benefit analysis and ROI.
  • Often preferred for communicating risk to business stakeholders.

Memory trick: Quantify for the cash, Qualify for the gut.

More Governance, Risk and Compliance questions