Offline·Progress will sync once you are back on the network.
Loading page
Free cheat sheet
Security+ Risk Management Cheat Sheet (SY0-701)
Everything you need for Domain 5 risk management on the CompTIA Security+ SY0-701 exam: the formulas, the four risk responses, recovery metrics, recovery sites, and the third-party agreements. Free, no account. Download the PDF or study it here.
Single Loss Expectancy: the cost of one incident (Asset Value x Exposure Factor).
ALE = SLE x ARO
Annualized Loss Expectancy: the yearly cost (one loss x how many per year).
Risk = Likelihood x Impact
The chance a threat exploits a vulnerability, weighted by how bad it is.
Worked example: a server worth $50,000 with a 20% exposure factor has an SLE of $10,000. If you expect the incident twice a year (ARO of 2), the ALE is $20,000.
Risk fundamentals and formulas
The vocabulary and the math. Risk is the chance a threat exploits a vulnerability, weighted by impact.
Risk = Likelihood x ImpactThe core idea: a threat exploiting a vulnerability, weighted by how likely it is and how bad it would be.
Vulnerability / Threat / RiskA vulnerability is a weakness, a threat is what could exploit it, and risk is the likelihood and impact if the two meet.
EF (Exposure Factor)The percentage of an asset's value lost in a single incident, from 0 to 100%.
SLE (Single Loss Expectancy)Asset Value x Exposure Factor. The cost of one occurrence.
ARO (Annualized Rate of Occurrence)How many times per year you expect the event to happen.
ALE (Annualized Loss Expectancy)SLE x ARO. The expected yearly cost of the risk.
Inherent vs residual riskInherent risk is before any controls; residual risk is what remains after controls are applied.
Risk appetite vs toleranceAppetite is how much risk an organization is willing to take overall; tolerance is the acceptable variance around it.
Responding to risk
Once a risk is identified, you choose a response. Know the four classic options.
AcceptTake no further action because the cost of control exceeds the risk. May be formalized as an exemption or exception.
AvoidStop the activity that creates the risk entirely.
Transfer (share)Shift the financial impact to a third party, such as insurance or outsourcing.
Mitigate (reduce)Apply controls to lower the likelihood or the impact.
Risk registerThe central record of each risk: owner, score, chosen response, and status.
Risk ownerThe person accountable for managing a specific risk.
Risk analysis types
How risks are measured and prioritized. The exam contrasts qualitative with quantitative.
QualitativeRates risk with labels such as high, medium, and low on a likelihood-impact matrix. Fast but subjective.
QuantitativeAssigns hard numbers and money: SLE, ARO, and ALE. Rigorous but data-heavy.
Risk matrix / heat mapPlots likelihood against impact to rank which risks to treat first.
KRI (Key Risk Indicator)A metric that signals rising risk before it is realized.
Assessment cadenceRisk assessments can be ad hoc, one-time, recurring, or continuous.
Continuity and recovery metrics
How resilience and disaster recovery are measured. These come out of the business impact analysis.
BIA (Business Impact Analysis)Identifies critical functions and the impact of their downtime, and sets the RTO and RPO.
RTO (Recovery Time Objective)Maximum tolerable time to restore a service after an outage. RTO = time.
RPO (Recovery Point Objective)Maximum tolerable data loss, measured back to the last good backup. RPO = data.
MTD (Maximum Tolerable Downtime)The longest a function can be down before serious harm. RTO must be shorter than MTD.
MTBF (Mean Time Between Failures)Average time between failures of a repairable system. Higher means more reliable.
MTTR (Mean Time To Repair)Average time to restore a failed system. Lower is better.
MTTF (Mean Time To Failure)Average lifespan of a non-repairable component.
Recovery sites and resilience
Where you fail over to, traded off by cost versus how fast they come up.
Hot siteFully equipped and running; fail over in minutes. Most expensive.
Warm siteHardware and connectivity ready, but needs data and setup. Comes up in hours.
Cold siteSpace and power only; everything must be brought in. Cheapest and slowest.
Geographic dispersionSpread sites and backups far enough apart that one disaster cannot hit them all.
High availabilityRedundancy, clustering, and load balancing to remove single points of failure.
Third-party agreements
The contracts and documents that govern vendor and partner relationships, all tested in Domain 5.
SLA (Service Level Agreement)Measurable commitments such as uptime, response times, and penalties.
MOU / MOA (Memorandum of Understanding/Agreement)A less formal statement of intent to cooperate; often not legally binding.
MSA (Master Service Agreement)Overarching terms that govern future work and individual statements of work.
SOW (Statement of Work)The specific deliverables, scope, and timeline of a project.
BPA (Business Partners Agreement)Terms between business partners, such as responsibilities and profit sharing.
NDA (Non-Disclosure Agreement)Legally binds the parties to keep shared information confidential.
AUP (Acceptable Use Policy)The rules for how employees may use company systems and data.
Governance, audits, and data roles
Who sets the rules, who checks them, and who is responsible for the data.
Policy / standard / procedure / guidelinePolicy is high-level intent, a standard is mandatory specifics, a procedure is step-by-step, and a guideline is recommended but optional.
Due care vs due diligenceDue care is taking reasonable action; due diligence is the ongoing investigation and monitoring that informs it.
Separation of dutiesSplit a sensitive task so no single person controls it end to end.
Internal vs external auditInternal audits are self-checks; independent external audits and attestation carry more trust.
Data owner vs custodianThe owner is accountable for the data and its classification; the custodian implements the controls day to day.
Controller vs processorUnder privacy law the controller decides why and how data is processed; the processor acts on the controller's behalf.
Drill mode
Test yourself on this sheet
Ten quick questions drawn from the 44 governance and risk terms on this page, with instant feedback. Reading a cheat sheet feels like studying; retrieving it is what makes it stick.
Domain 5 is a fifth of the exam
Risk and governance make up 20% of SY0-701. SecPlus Mastery teaches every Domain 5 objective and drills it with over 1,000 practice questions, mock exams, and spaced review across all five domains.
SLE = Asset Value x Exposure Factor (the cost of one incident). ARO is the Annualized Rate of Occurrence (how many times a year you expect it). ALE = SLE x ARO (the yearly cost). These are the core Domain 5 calculations.
What is the difference between RTO and RPO?
RTO (Recovery Time Objective) is how long you can be down before service must be restored. RPO (Recovery Point Objective) is how much data you can afford to lose, measured back to your last good backup. RTO is time; RPO is data.
What are the four ways to respond to risk?
Accept, avoid, transfer (for example, buying insurance), and mitigate (apply controls to reduce likelihood or impact). The exam may also mention risk acceptance with an exemption or exception.
What is the difference between qualitative and quantitative risk analysis?
Quantitative analysis assigns hard numbers, such as SLE, ARO, and ALE in dollars. Qualitative analysis uses ratings like high, medium, and low. Most real assessments blend the two.
What do SLA, MOU, MSA, and BPA mean?
SLA is a Service Level Agreement (performance and uptime commitments). MOU/MOA is a less formal statement of intent. MSA is a Master Service Agreement (overarching terms). BPA is a Business Partners Agreement. SOW is a Statement of Work (the specific deliverables). These third-party agreements are tested in Domain 5.
Is this risk management cheat sheet free?
Yes. The full cheat sheet and the printable PDF are free, with no account, payment, or signup required.