📖 What is Annual Rate of Occurrence (ARO)?
Annual Rate of Occurrence (ARO) is the estimated frequency with which a specific threat is expected to occur within a single year. It is expressed as a number, such as 0.1 for once every ten years or 2 for twice a year.
"ARO is the 'how often' part of the risk equation. When calculating ALE, always multiply the SLE by the ARO."
📚 Certification: Certified Information Systems Security Professional (CISSP)
🔑 What are the Key Concepts of Annual Rate of Occurrence (ARO)?
- ▸ ARO is a core component of quantitative risk analysis, providing a numerical value to represent the likelihood of a threat occurring annually.
- ▸ It is expressed as a number; for instance, an event occurring once every five years is calculated as an ARO of 0.2.
- ▸ In the risk equation, ARO is multiplied by the Single Loss Expectancy (SLE) to derive the Annual Loss Expectancy (ALE) for budgeting.
- ▸ Values are typically derived from historical incident logs, industry-standard actuarial tables, or expert estimations when empirical data is missing.
- ▸ ARO focuses specifically on frequency over a one-year period, distinguishing it from qualitative assessments that use descriptive labels like 'likely' or 'unlikely'.
🎯 How does Annual Rate of Occurrence (ARO) appear on the CISSP Exam?
A scenario might provide the cost of a single data breach (SLE) and the frequency of such breaches (ARO), asking you to calculate the Annual Loss Expectancy (ALE) to justify a security control.
You may be asked to convert a long-term event frequency into an ARO, such as a catastrophic earthquake occurring once every 100 years, requiring a calculation of 0.01.
Expect questions where you must compare the ARO of multiple threats to determine which risk possesses the highest annual financial impact, helping prioritize the organization's risk response strategy.
❓ Frequently Asked Questions
How does ARO affect the decision to accept a risk?
If the ARO is extremely low and the cost of the countermeasure exceeds the resulting ALE, the organization may decide that accepting the risk is more cost-effective than mitigating it.
Can ARO be greater than 1.0?
Yes. If a specific threat, such as a phishing attack or a system glitch, occurs multiple times per year, the ARO will be an integer greater than 1 (e.g., ARO of 12 for monthly occurrences).