712-50 Question 188
Single answerQuantitative Rational Decision MakingA newly appointed CISO must decide whether to fund a cloud email security upgrade for the next fiscal year. The current environment experiences business email compromise (BEC) and malware incidents. Based on internal loss data and finance estimates, the security team calculates the following annualized loss expectancy (ALE): BEC-related losses = $420,000 per year; email-borne malware recovery and downtime = $180,000 per year. The proposed upgrade would cost $260,000 annually and is expected to reduce BEC losses by 50% and malware-related losses by 70%. The CFO asks for a quantitative justification using rational decision-making principles. What is the MOST appropriate recommendation?
- A
Approve the upgrade because the expected annual loss reduction is $336,000, which exceeds the annual control cost by $76,000.
- B
Reject the upgrade because the control does not eliminate all email risk and therefore cannot be justified quantitatively.
- C
Approve the upgrade only if the annualized rate of occurrence (ARO) for both incident types increases next year.
- D
Reject the upgrade because the combined single loss expectancy (SLE) was not provided, so ALE-based analysis is incomplete.
Show answer and explanation
Correct answer: A
Explanation
This question tests quantitative rational decision making by requiring the candidate to evaluate a security investment using expected annual loss reduction versus control cost. A common formula in information risk management is ALE = SLE x ARO, but once ALE is known or credibly estimated from historical data and financial analysis, it can be used directly for decision support. The appropriate approach is to estimate the control's effect on relevant loss categories, calculate the expected reduction in ALE, and compare that value to the annual cost of the safeguard. In this case, the expected annual reduction is $336,000, exceeding the annual cost of $260,000, so the net expected value is positive. This aligns with established security and risk management practices found in sources such as NIST SP 800-30 for risk assessment concepts and standard cost-benefit reasoning used in governance and enterprise risk management. A CISO should also consider non-financial factors such as regulatory exposure, brand impact, and residual risk tolerance, but the CFO specifically requested a quantitative justification, and the numbers support approval.
- A. Correct.
Correct. Quantitative rational decision making compares the expected reduction in annual loss to the annual cost of the control. Current total ALE is $600,000 ($420,000 + $180,000). Expected reduction is $210,000 for BEC (50% of $420,000) plus $126,000 for malware (70% of $180,000), totaling $336,000. Net expected benefit is $76,000 per year ($336,000 - $260,000). On a purely quantitative basis, the control is justified because the expected annual savings exceed the annual cost.
- B. Incorrect.
Incorrect. A control does not need to eliminate all risk to be economically justified. In quantitative risk analysis, a control is typically justified if the reduction in ALE exceeds its cost and aligns with business risk tolerance. Requiring total elimination of risk reflects a common misconception and is inconsistent with cost-benefit-based security investment decisions.
- C. Incorrect.
Incorrect. The decision should be based on current credible estimates and expected value, not delayed until future incident frequency changes. ARO is one component used to derive ALE, but the scenario already provides ALE values directly. Waiting for ARO to increase would ignore available quantitative evidence and could expose the organization to avoidable losses.
- D. Incorrect.
Incorrect. While SLE and ARO are often used to calculate ALE, they are not required if ALE has already been reliably estimated. Since the scenario provides annualized loss values and projected control effectiveness, the CISO can perform a valid cost-benefit analysis without recalculating from SLE.