Here is the question: What is the ALE for phishing emails for the company, in pounds; e.g. 203,760?
Here is the scenario: Phishing is of major concern to an organisation, so they have begun to monitor how big a risk it is posing. On average, 80 phishing emails are sent to everyone in the company per day. The company email filters stop 99.8% of these getting through. Of the emails that do get through, 30% of employees click on the link. Out of those employees, 2% expose their company login details to the phishing website. For every set of company login details that are exposed to the hackers, the company has found that it costs them £225. The company has 7,000 employees.
ALE = SLE x ARO
annual loss expectency = single loss expectancy x annual rate of occurance
SLE = AV x EF
single loss expectancy = asset value x exposure factor
ARO is the probability that something will happen per year; ARO in the example above is 0.5 floods per year. The single loss expectancy (SLE) is the cost of a single loss and is broken down further into two parts: the Asset Value (AV) and the Exposure Factor (EF):
I'm stuck on the exposure factor and annual rate of occurence.
Here is the scenario: Phishing is of major concern to an organisation, so they have begun to monitor how big a risk it is posing. On average, 80 phishing emails are sent to everyone in the company per day. The company email filters stop 99.8% of these getting through. Of the emails that do get through, 30% of employees click on the link. Out of those employees, 2% expose their company login details to the phishing website. For every set of company login details that are exposed to the hackers, the company has found that it costs them £225. The company has 7,000 employees.
ALE = SLE x ARO
annual loss expectency = single loss expectancy x annual rate of occurance
SLE = AV x EF
single loss expectancy = asset value x exposure factor
ARO is the probability that something will happen per year; ARO in the example above is 0.5 floods per year. The single loss expectancy (SLE) is the cost of a single loss and is broken down further into two parts: the Asset Value (AV) and the Exposure Factor (EF):
I'm stuck on the exposure factor and annual rate of occurence.