Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Risk assessment is a fundamental requirement of network security for any organization. It is an essential part of a sound security policy for any organization. Risk analysis can be performed either in a quantitative or qualitative way.
In a quantitative approach, the probability of a network security event occurring is outlined, and the associated loss is identified. The result of a quantitative risk analysis is an annual loss expectancy (ALE), which is calculated for every network event as the product of the potential loss associated with a network security breach with its probability. This process provides for a prioritized quantitative outline of the top-ticket network security threats that must be secured.