<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HELP with Risk ALE calculation question in Training in CISSP Study Group</title>
    <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82866#M2058</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/160496067"&gt;@Fishbone&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi, I dont understand the calculations in the solution of this question.&lt;/P&gt;&lt;P&gt;If the CPU burns every 9 months, shouldn't ARO be 1.33 as it is expected to happen more than once a year, instead of 0.75 as the solution states??&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Given the scenario described, you are correct. If something occurs more frequently than once per year (i.e., once every nine months), then the ARO is greater than 1 (1.33 if it is once every nine months). In the abstract, the math should be:&lt;/P&gt;&lt;P&gt;$1,250 (value) X .33 (exposure factor) = $412.50&lt;/P&gt;&lt;P&gt;Annualized Rate of Occurrence&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= 1.33&lt;/P&gt;&lt;P&gt;Annual Loss Expectancy&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = $536.25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question seems flawed. The number of laptops is irrelevant (they even state the contract is per laptop per annum). Therefore, none of the answers (since they reference single vs. multiple failures) is correct. The very reason we do things like ARO, exposure factor, etc. is to normalize across an inventory. In other words exposure factor could/should already account for what percentage of the inventory is subject to the failure (e.g., one-third).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Further aside, "asset value" is not a constant. It depreciates. For example, if you have two-year old laptop and its CPU fails, no one in their right mind would pay (whether out of pocket or with a service agreement) to replace the CPU. Instead, you buy a new laptop, get twice the capability for roughly the same price you paid two years ago (according to Moore's Law).&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2025 19:25:46 GMT</pubDate>
    <dc:creator>JoePete</dc:creator>
    <dc:date>2025-08-05T19:25:46Z</dc:date>
    <item>
      <title>HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82731#M2037</link>
      <description>&lt;P&gt;Hi, I dont understand the calculations in the solution of this question.&lt;/P&gt;&lt;P&gt;If the CPU burns every 9 months, shouldn't ARO be 1.33 as it is expected to happen more than once a year, instead of 0.75 as the solution states??&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;H3&gt;&lt;FONT size="4"&gt;You have been tasked with performing a risk assessment using the "loss expectancy" model on the organization's laptop computers as there seems to be a high failure rate.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;You use the formula ALE (Annual Loss Expectancy) = SLE (Single Loss Expectancy) x ARO (Annual Rate of Occurrence), with the SLE being calculated by multiplying the AV (Asset Value) by the EF (exposure factor).&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;After consultation with the various stakeholders, it seems that besides a problem with the central processing unit (CPU), the laptops are reliable and robust.&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;Working with the following figures, what is the SLE for each laptop?&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;AV - $1250.00&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;EF – 33% (the cost to replace the CPU)&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;ARO - CPU burnout every 9 months&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;Your laptop supplier is offering a support and maintenance contract for $600 per annum, per laptop, which includes parts and labor.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;Calculate the ALE. Is the support contract cost-effective?&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;A - Given the ALE and assuming a single failure: no, it is not&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;H4&gt;B - Given the ALE and assuming a single failure: yes, it is&lt;/H4&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H4&gt;C - Given the ALE and assuming multiple failures: no, it is not&lt;/H4&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;H4&gt;D - Given the ALE and assuming multiple failures: yes, it is&lt;/H4&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;H5&gt;&amp;nbsp;&lt;/H5&gt;&lt;H5&gt;Explanation&lt;/H5&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;H4&gt;To calculate the ALE, we would need to take the SLE $412.50 and multiply it by the projected failure rate of once every nine months or 0.75 (the ARO). This gives us an ALE of $309.38, as the support contract will cost the organization $600. Given the information that a single yearly failure costs $309.38 compared to the support contract's cost of $600 annually, then we can say the support contract is not cost effective.&lt;/H4&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 Aug 2025 02:34:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82731#M2037</guid>
      <dc:creator>Fishbone</dc:creator>
      <dc:date>2025-08-01T02:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82742#M2038</link>
      <description>&lt;P&gt;It looks like you miscalculated. Assuming you calculated 12(mo) / 9(mo) = 1.33, that is not correct. Nine months is 3/4 of one year(12 mo.), so .75. 1.33 would assume that 9 months occur more than once in a 12-month period, which, of course, it does not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you came up with 1.33 by another means, please let me know, and I'll try to help break it down.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 13:01:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82742#M2038</guid>
      <dc:creator>George_G</dc:creator>
      <dc:date>2025-08-01T13:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82825#M2050</link>
      <description>&lt;P&gt;Hi, thanks for tour reply.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Since the failure occurs every 9 months, my understanding is that the &lt;STRONG&gt;annualized occurrence&lt;/STRONG&gt; must be greater than 1, not less, because it happens at least once a year. If it occurs once every 9 months, over a 12-month period, it would occur 12/9 times, which equals &lt;STRONG&gt;1.33&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another way to look at it is that if it occurs every 9 months, in a 3-year period (36 months), it would occur 4 times. Therefore, the annual rate would be 4/3, which is also &lt;STRONG&gt;1.33&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 17:14:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82825#M2050</guid>
      <dc:creator>Fishbone</dc:creator>
      <dc:date>2025-08-04T17:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82829#M2051</link>
      <description>&lt;P&gt;hmm, interesting. I kind of see why you'd think this way and I even ran the question through AI and the output also explained it this way, although it chose C as the answer. However, my brain still wants to think that it can only happen once per year. My next question would be the source of the question and the quality of it. Maybe others will chime in because now I'm invested and would really like clarification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***edit***&lt;/P&gt;&lt;P&gt;so after a little more reading and clarification for myself, the ARO is the number of event per year, not percentage of a year. So you would be correct, that it would be 1.33.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 00:28:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82829#M2051</guid>
      <dc:creator>George_G</dc:creator>
      <dc:date>2025-08-05T00:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82839#M2052</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fishbone_0-1754359624415.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/10105i6CDA8E143E138D45/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Fishbone_0-1754359624415.png" alt="Fishbone_0-1754359624415.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can find this question in the official self paced ISC2 training.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 02:09:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82839#M2052</guid>
      <dc:creator>Fishbone</dc:creator>
      <dc:date>2025-08-05T02:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82865#M2057</link>
      <description>&lt;P&gt;Hopefully, we'll get some other perspectives on this. Another point to consider that validates what you're saying is if the event happens once per year, the ARO = 1. If it happens every 6 months, then the ARO = 2. So every 9 months is somewhere in between that (1.33). I'm stumped on the explanation for this one.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 18:36:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82865#M2057</guid>
      <dc:creator>George_G</dc:creator>
      <dc:date>2025-08-05T18:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82866#M2058</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/160496067"&gt;@Fishbone&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi, I dont understand the calculations in the solution of this question.&lt;/P&gt;&lt;P&gt;If the CPU burns every 9 months, shouldn't ARO be 1.33 as it is expected to happen more than once a year, instead of 0.75 as the solution states??&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Given the scenario described, you are correct. If something occurs more frequently than once per year (i.e., once every nine months), then the ARO is greater than 1 (1.33 if it is once every nine months). In the abstract, the math should be:&lt;/P&gt;&lt;P&gt;$1,250 (value) X .33 (exposure factor) = $412.50&lt;/P&gt;&lt;P&gt;Annualized Rate of Occurrence&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= 1.33&lt;/P&gt;&lt;P&gt;Annual Loss Expectancy&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = $536.25&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question seems flawed. The number of laptops is irrelevant (they even state the contract is per laptop per annum). Therefore, none of the answers (since they reference single vs. multiple failures) is correct. The very reason we do things like ARO, exposure factor, etc. is to normalize across an inventory. In other words exposure factor could/should already account for what percentage of the inventory is subject to the failure (e.g., one-third).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Further aside, "asset value" is not a constant. It depreciates. For example, if you have two-year old laptop and its CPU fails, no one in their right mind would pay (whether out of pocket or with a service agreement) to replace the CPU. Instead, you buy a new laptop, get twice the capability for roughly the same price you paid two years ago (according to Moore's Law).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 19:25:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/82866#M2058</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2025-08-05T19:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: HELP with Risk ALE calculation question in Training</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/89388#M2411</link>
      <description>&lt;P&gt;I have to say that I'm disappointed here. This thread is over 6 months old and the "guide" still has a deeply flawed calculation as is example of how to do it... The really scary part is that I only see 6 people talking about it here, and even they are questioning themselves...you're not wrong. 0.75 in that calculation is for an event every 18 months. 9 months is 1 &amp;amp; 1/3 ARO...Which in the phone example in the training is an $80 ALE...so...buy the insurance... It makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said, when you get to the questions...the CPUs... If they are dying every 9 months, someone really messed up. That said, even calculating at 1&amp;amp;1/3 ARO you're still coming in under 600 (550) so insurance/ transference doesn't make sense&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Considering what I'm paying for this, and the code of ethics this organization purports to hold so highly, I would hope that when they discovered that their training materials were misleading people something would be done immediately. I've sent an email... Hopefully they will fix this and help restore my faith in the training i paid for. I know a lot of this information coming in... I'm taking the training for the stuff I don't know. When I see something i know misrepresented for months...well...i don't want to be "that guy"...but... I'm going to start asking questions&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 03:53:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/HELP-with-Risk-ALE-calculation-question-in-Training/m-p/89388#M2411</guid>
      <dc:creator>Guitarpy</dc:creator>
      <dc:date>2026-04-24T03:53:54Z</dc:date>
    </item>
  </channel>
</rss>

