Annualized Rate of Occurrence (ARO): A measure used in risk assessment that estimates the likelihood of a particular security incident occurring within a given year. It’s a probabilistic estimate, often based on historical data or expert judgment. By considering the ARO alongside the potential impact of an incident, organizations can better understand and manage their risk exposure, helping to prioritize security investments and mitigation strategies. If it is likely to happen 5 times a year the ARO is 5, if it is likely to happen every 5 years the ARO is 0.2.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D2: Information security risk management | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index