QS0011-03: Risk Analysis Flashcards

1
Q

QS0011-03: Risk Analysis

What is the meaning of Risk Analysis?

A

Risk analysis identifies and analyzes potential issues that could negatively impact key business initiatives or projects. This process is done to help organizations avoid or mitigate those risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

QS0011-02: Risk Analysis

Name examples of the tools for measuring risk.

A

SWOT, fishbone, risk registers, and risk matrices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

QS0011-02: Risk Analysis

What are the three security objectives?

A
  1. Confidentiality
  2. Integrity
  3. Availability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

QS0011-02: Risk Analysis

Which two factors determine the risk level in the Risk Assessment matrix?

A

The risk matrix is based on two intersecting factors: the likelihood that the risk event will occur and the potential impact the risk event will have on the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

QS0011-02: Risk Analysis

Describe three levels of a potential impact

A
  • *1. Low:** “The potential impact is low if—The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals.
  • *2. Moderate:** “The potential impact is moderate if—The loss of confidentiality, integrity, or availability could be expected to have a severe adverse effect on organizational operations, organizational assets, or individuals.
  • *3. High:** “The potential impact is high if—The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

QS0011-02: Risk Analysis

What are the three steps of a Risk Analysis?

A
  1. Risk Assessment
  2. Risk Treatment
  3. Risk Review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the steps in the Risk Assessment?

A
  1. Identification
  2. Analyze
  3. Evaluation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What events need to be included in the Risk Review?

A
  1. Change control
  2. CAPA/Deviations
  3. Security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly