Home > Glossary > Certified Information Systems Security Professional > Annual Rate of Occurrence (ARO)

📖 What is Annual Rate of Occurrence (ARO)?

Annual Rate of Occurrence (ARO) is the estimated frequency with which a specific threat is expected to occur within a single year. It is expressed as a number, such as 0.1 for once every ten years or 2 for twice a year.

🥋 Sensei Says:

"ARO is the 'how often' part of the risk equation. When calculating ALE, always multiply the SLE by the ARO."

📚 Certification: Certified Information Systems Security Professional (CISSP)

🔑 What are the Key Concepts of Annual Rate of Occurrence (ARO)?

  • ARO is a core component of quantitative risk analysis, providing a numerical value to represent the likelihood of a threat occurring annually.
  • It is expressed as a number; for instance, an event occurring once every five years is calculated as an ARO of 0.2.
  • In the risk equation, ARO is multiplied by the Single Loss Expectancy (SLE) to derive the Annual Loss Expectancy (ALE) for budgeting.
  • Values are typically derived from historical incident logs, industry-standard actuarial tables, or expert estimations when empirical data is missing.
  • ARO focuses specifically on frequency over a one-year period, distinguishing it from qualitative assessments that use descriptive labels like 'likely' or 'unlikely'.

🎯 How does Annual Rate of Occurrence (ARO) appear on the CISSP Exam?

A scenario might provide the cost of a single data breach (SLE) and the frequency of such breaches (ARO), asking you to calculate the Annual Loss Expectancy (ALE) to justify a security control.

You may be asked to convert a long-term event frequency into an ARO, such as a catastrophic earthquake occurring once every 100 years, requiring a calculation of 0.01.

Expect questions where you must compare the ARO of multiple threats to determine which risk possesses the highest annual financial impact, helping prioritize the organization's risk response strategy.

❓ Frequently Asked Questions

How does ARO affect the decision to accept a risk?

If the ARO is extremely low and the cost of the countermeasure exceeds the resulting ALE, the organization may decide that accepting the risk is more cost-effective than mitigating it.


Can ARO be greater than 1.0?

Yes. If a specific threat, such as a phishing attack or a system glitch, occurs multiple times per year, the ARO will be an integer greater than 1 (e.g., ARO of 12 for monthly occurrences).

Related Terms from Certified Information Systems Security Professional

📝 Related Study Guides

Study Guide 10 min read

How to Pass the CISSP Exam: A Realistic 2026 Study Plan

To pass the CISSP, you must transition from a technical mindset to a managerial one, focusing on risk management and policy over implementation. Success requires a 3-6 month study plan covering all eight domains, using adaptive practice exams to identify gaps and mastering the "mile wide, inch deep" breadth of the CBK.

Career Guide 10 min read

CISSP Experience Requirements: How to Get Your Waiver in 2026

To earn the CISSP, you need five years of cumulative, paid work experience in two or more of the eight CISSP domains. You can obtain a one-year waiver through a four-year college degree or approved professional certifications. Those lacking full experience can become an Associate of ISC2 after passing the exam.

Deep Dive 8 min read

Kerberos Authentication Explained for the CISSP Exam

Kerberos is a ticket-based authentication protocol designed to provide strong authentication for client/server applications by using secret-key cryptography. It utilizes a trusted third party called the Key Distribution Center (KDC) to issue tickets, enabling Single Sign-On (SSO) and preventing replay attacks through the use of synchronized timestamps.

🧠

Test Your Knowledge

Think you understand Annual Rate of Occurrence (ARO)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium