Jane has suggested we implement full disk encryption on our laptops. Our organization on average loses 25 laptops per year and currently it costs us $10,000 per laptop, of that $1,000 is the cost of the laptop and the $9,000 is from non encrypted data being exposed. How much can the countermeasure cost per year and we would break even with the current ALE?

A: 2250000

B: 225000

C: 250000

D: 22500

CBK 1: Security and Risk Management

Source: ThorTeaches.com practice tests

Answer

B: The Laptop ($1,000) + PII ($9,000) per loss (AV), It is a 100% loss, it is gone (EF), Loss per laptop is $10,000 (AV) x 100% EF) = (SLE), The organization loses 25 Laptops Per Year (ARO), The annualized loss is $250,000 (ALE).

## 9 Comments

C. AV = $10,000

EF = 100%

SLE = $10,000

ARO = 25

ALE = $10,000 x 25= $250,000

$1000 is the quantitative value and $9000 is the qualitative value, for a combined asset value of $10,000.

