3.1.3. Risk Assessment Methodologies
💡 First Principle: Numbers feel objective, but a quantitative estimate is only as trustworthy as the data feeding it — forcing false quantitative precision onto a risk with no loss history is often less accurate than an honest qualitative judgment, not more.
Qualitative risk assessment scores likelihood and impact on descriptive scales (Low/Medium/High) plotted on a risk matrix, relying on expert judgment where hard loss data doesn't exist. Quantitative assessment attempts to put a dollar figure on expected loss, most commonly via Annualized Loss Expectancy (ALE) = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO) — for example, an SLE of $200,000 for a specific outage scenario expected once every four years (ARO = 0.25) yields an ALE of $50,000. Quantitative output looks more rigorous, but that rigor is only real when the inputs — SLE and ARO — are themselves grounded in actual loss history or reliable actuarial-style data, which is frequently unavailable for novel or emerging risks.
SLE itself isn't a single input — it breaks down further into SLE = Asset Value (AV) × Exposure Factor (EF), where AV is the asset's value and EF is the percentage of that value a single occurrence of the risk event would destroy. A $100,000 server with a 50% exposure to fire damage has an SLE of $50,000 — the AV/EF breakdown is what a risk manager actually has to estimate before an ALE calculation is even possible.
The two approaches are complementary rather than competing: a mature program often uses qualitative screening to prioritize which risks are worth the additional effort of quantitative analysis, reserving ALE-style calculations for the handful of risks with enough reliable data and enough stakes to justify the precision.
⚠️ Exam Trap: Quantitative analysis is often assumed to be strictly superior because it produces a specific number. The correct reasoning recognizes that quantitative methods are only as good as their input data — for novel risks with no loss history, forced quantification creates false precision, and a well-reasoned qualitative rating can be the more honest assessment.
⚠️ Exam Trap: A risk register entry, once created, is sometimes assumed to mean the risk has been "handled." Identification is only the first step of the process shown above — an un-owned, un-treated register entry is documented exposure, not managed risk, until it moves through the treatment and ownership steps covered in 3.2.
Reflection Question: A risk analyst produces an ALE of exactly $73,412 for a brand-new type of attack with no organizational loss history to draw on. Should this specific figure be trusted more than a qualitative "High" rating from an experienced risk manager? Why or why not?