10: 1 Risk Analysis Flashcards

(30 cards)

1
Q

Risk Assessment

A

Identifying and triaging the risks facing an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat

A

External force that jeopardizes security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat vector

A

Method an actor uses to get to their target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerability

A

Weakness in security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk

A

Combination of vulnerability and a corresponding threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Factors that prioritize a risk

A

Likelihood and Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Qualitativee Risk Assessment

A

Use subjective ratings to evaluate risk (Low, medium, high)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Quantitative Risk Assessment

A

Uses objective numeric ratings to evaluate risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Quantitative Risk Assessment is performed on?

A

Single risk and asset pair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AV

A

Asset value - the dollar value of an asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AV Techniques (3)

A

Original Cost Technique
Depreciated Cost Technique
Replacement Cost Technique

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

EF

A

Exposure Factor- Expected percentage of damage to an asset (%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SLE

A

Single-Loss Expectancy - Expected dollar loss if a risk occurs one time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Formula for SLE

A

SLE = AV * EF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ARO

A

Annualized Rate of Occurrence- Number of times a risk is expected to occur each year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ALE

A

Annualized Loss Expectancy - Expected dollar loss from a risk in any given year

17
Q

Formula for ALE

A

ALE = SLE * ARO

18
Q

MTTF

A

Mean Time to Failure - Average time a nonrepairable assets will last

19
Q

MTBF

A

Mean Time Between Failures - Average time between failures of a repairable asset

20
Q

MTTR

A

Meant Time to Repair - Average time required to return a repairable component to service

21
Q

Internal Risk

A

Arise from within the organization

22
Q

Address Internal Risks?

A

Using internal controls

23
Q

External Risk

A

Arise from outside the organization

24
Q

Address External Risks?

A

Using internal controls

25
Multiparty Risks
Shared across many organizations (i.e. software as a service provider is compromised)
26
Legacy Risks
Arise from unsupportable systems
27
Software license compliance issues
Risk of fines and legal action
28
Data Classification Policies
Assign information into categories that determine storage, handling, and access requirements
29
Assign classification based upon
Sensitivity of Information, Criticality of Information
30
Types of Sensitive Customer Information
PII, Financial Information, Healthcare Information (HIPAA)