The standard quantitative risk formula: how much a specific risk is expected to cost your organization per year, projected over the time you'll actually carry it, and whether fixing it is worth the price.
A rare-but-severe risk can look small as a single annual number but add up to something very real over however many years you'll actually be exposed to it. This is the number that belongs in a capital-expense conversation, not the bare annual ALE.
If a proposed security control costs less than the ALE it addresses - or, for a one-time fix, less than the total loss expected over however many years you'd otherwise carry the risk - it's generally worth implementing. This is the core logic behind quantitative risk analysis, and it comes up constantly in real budget conversations, not just on the CISSP exam.
The math has a real blind spot worth knowing: ALE only prices the direct loss. It doesn't account for compliance exposure, insurance premium impact, downtime beyond the asset itself, or reputational damage - all of which can tip a "the math says no" decision the other way in practice.
Related terms: SLE • ARO • ALE
Want to actually practice risk management scenarios, not just calculate one number?
Practice Free on Zamlom