Question: Exercise 1 As a junior Security Analyst at Zinder Inc., your boss asked you to perform a classic risk analysis in order to help the
Exercise 1 As a junior Security Analyst at Zinder Inc., your boss asked you to perform a classic risk analysis in order to help the company make a decision about whether or not to investing in one of the countermeasures that the company is planning on implementing. The countermeasures are meant to help protect the company's multifunction server (that has a value of $15,000) and all the software and databases it host against security attacks. The value of the software and the databases is estimated at $485,000. In case of a successful attack, it is expected that 80 percent of the asset's value will be lost. An attack is expected to be successful once every five years. Countermeasure A will cut the amount lost per incident by 75 percent. Countermeasure B will cut the frequency of successful attack in half. Countermeasure A will cost $30,000 per year, while Countermeasure B will cost $5,000 per year. Question 1: Conduct a classic risk analysis using the template below. Note: you need to calculate all the numbers and use them to complete this template (table). Base Case Countermeasure Asset Value AV Exposure Factor Single Loss Expectancy SLE Annuaired Rate of Occurrence Annualized Loss Expectancy ALE ALE Raduction for Countermeasure Annuaed Countessure Cost Anna Courr Net ure Value Question 2: Based on the results of the risk analysis, which of the two countermeasures should Zinder Inc. implement (if any). Explain your choice of countermeasure by providing supporting evidence from the result the risk analysis you performed when answering Question 1
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
