Is Risk-Based Security Really Possible?
...ALE = (Impact of the event in $$) * (Number of times in a year the event will happen
So, you calculate your ALE and that's the maximum you should spend to mitigate that risk
If the real world was that simple, we'd all use ALE to plan our security strategies. But ALE is fundamentally wrong for for information security. I'll concede that ALE...





