CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentHard

A global conglomerate is performing a quantitative risk analysis for its cloud infrastructure. The risk manager is struggling to obtain precise historical data for the Annualized Rate of Occurrence (ARO) for specific cloud-native security incidents. Which of the following approaches would be MOST appropriate to estimate ARO in this situation?

  1. AUse industry benchmarks and expert judgment from cloud security specialists.
  2. BConduct a detailed penetration test to determine exact ARO values.
  3. CAssume a worst-case scenario (ARO=1.0) for all incidents.
  4. DExclude incidents with insufficient data from the risk analysis.
Show answer & explanation

Correct answer: A. Use industry benchmarks and expert judgment from cloud security specialists.

When precise historical data is unavailable, especially for emerging technologies or specific incident types, leveraging industry benchmarks and expert judgment from specialists is the most appropriate and pragmatic approach to estimate ARO. This combines external data with informed qualitative assessment to derive a quantitative estimate.

Why the other options are wrong

  • B. A penetration test identifies vulnerabilities and potential impact, but it does not directly determine the Annualized Rate of Occurrence (frequency) of specific incidents over a year. It's a point-in-time assessment.
  • C. Assuming a worst-case ARO=1.0 is overly pessimistic and will skew the risk analysis, making all risks appear critical.
  • D. Excluding risks with insufficient data is poor risk management; it means ignoring potential threats rather than estimating them.

ARO Estimation Challenges

Difficulties in accurately determining the Annualized Rate of Occurrence due to lack of historical data, unique environments, or emerging threats.

  • Common in quantitative risk analysis.
  • Requires alternative methods when direct data is unavailable.
  • Expert judgment and industry data are key alternatives.

Memory trick: When the ARO data is a mystery, consult the wise and look at the neighbors.

More IT Risk Assessment questions