Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-27-2007, 07:39 AM
umd.risksurvey@gmail.com
Guest
 
Posts: n/a
Default Security Questions- A graduate student needs help

Dear All:

Hi all I am a Graduate Student at UMD and am working on a paper on
security risk perception. I was wondering if you good souls would
find it in your heart to help a poor (overworked underpaid) graduate
student. I will be grateful if you can take a few minutes out to fill
this 5 question survey. I will not be able to disclose information
about this paper as it may bias your reply. But I will be happy to
share the paper with you if you are interested once it is written. The
paper is about security risk assessment off course.

The survey is very simple below are basic definitions of risk
assessment which are followed by 5 questions. I assure you that this
is not SPAM and the reason I am using e-mail instead of a webpage is
that often people don't click the link to fill in a small survey. The
question regarding your job function is there because I can classify
the response accordingly.

Thank you for your help. May god bless you for helping the poor and
needy.

Regards,

S. Hull

DEINITIONS
--------Annualized Loss Expectancy (ALE)-----
Annualized Loss Expectancy (ALE) is the expected monetary loss that
can be expected for an asset due to a risk over a one year period. It
is defined as:

ALE baseline = SLE * ARO
where SLE is the Single Loss Expectancy and ARO is the Annualized Rate
of Occurrence.

---------Single Loss Expectancy-------

The Single Loss Expectancy (SLE) is the expected monetary loss every
time a risk occurs. The Single Loss Expectancy, Asset Value (AV), and
exposure factor (EF) are related by the formula:

SLE = AV * EF

Where asset value (AV) is a monetary value assigned to an asset and
exposure factor ( EF) is the proportion of an asset's value that is
likely to be destroyed by a particular risk, expressed as a percentage

Annualized Rate of Occurrence is the probability that a risk will
occur in a particular year

-------Benefits of safeguard---------

The savings or reduction in loss is given by

S = ALE baseline - ALE with new safeguard

The benefit from investment is equivalent to the reduction in loss and
is given by

B= Loss Reduction
Alternative Explanation

An alternative explanation of ALE is as given below.

ALE= (Expected Rate of Loss) x (value of the loss)

The savings or reduction in loss is given by

S = ALE baseline - ALE with new safeguard

The benefit from investment is equivalent to the reduction in loss and
is given by

B= Loss Reduction


QUESTIONS

1. ALE with new safeguard < ALE baseline
______ True
______ False
______ Neither true nor false
______ Can't say

Answer:

2. Introduction of a safeguard
a. Increases risk
b. Decreases risk
c. Does not change the risk
d. All of the above (a, b and c)
e. Introduces new risk
Answer:

3. Introduction of a new safeguard
a. Does not impact the effectiveness of other safeguards
b. Decreases the effectiveness of other safeguards
c. Increases the effectiveness of other safeguards
d. May impact the effectiveness of other safeguards
Answer:

4. My role in security decision is
a. Security Analyst
b. Security Administrators
c. Decision Maker
d. System Administrator
e. ___________________
Answer:

5. When it comes to security risk assessment
a. I am an expert
b. I am new to this concept
c. I am familiar with the concept
d. I use it all the time
e. ___________________
Answer:


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 07:38 PM
FBI Monitoring Your Computer And Reading Material re. Patriot Act tightwad alt.computer.security 2 11-08-2005 09:21 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 05:02 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45