4.0 - Vulnerability Assessment and Risk Management Flashcards
(38 cards)
What three elements need to exist in order for there to be risk?
An asset, a vulnerability, and a threat
What is risk?
Potential loss of CIA
What do tools like Nessus or Open VAS do?
They’re vulnerability scanners
CVSS stands for…
Common Vulnerability Scoring System
In CVSS, a higher number means ____.
riskier
Define “true positive.”
A vulnerability exists and was detected.
Define “true negative.”
No vulnerability exists and none were detected.
Define “false positive.”
No vulnerability exists yet one was mistakenly detected.
Define “false negative.”
A vulnerability exists but was not detected.
Qualitative risk analysis matches _____ to ______.
Likelihood to impact
What is SLE?
Single Loss Expectancy - the financial cost of a risk being realized
P. 230
What is ARO?
Annualized Rate of Occurrence - how many losses are expected this year
What is ALE?
Annualized Loss Expectancy - financial impact over a year
What is the basic quantitative analysis equation?
SLE x ARO = ALE
What are the three data states?
Data at rest, data in motion, data in use
What are the four risk management strategies?
Mitigation, Avoidance, Transference, Acceptance
What are the four controls in risk mitigation?
Preventive, detective, corrective, deterrent
What are the three categories of threat intelligence?
Tactical, Operational, and Strategic Intelligence
Name two vulnerability databases.
Common Vulnerabilities and Exposures (CVE)
National Vulnerability Database (NVD)
What are the four CVSS exploitability metrics?
Attack Vector
Attack Complexity
Privileges Required
User Interaction
What are the three CVSS impact metrics?
Data disclosure (Confidentiality)
Data alteration (Integrity)
Downtime or data loss (Availability)
What is SCAP?
Security Content Automation Protocol, a vulnerability assessment tool.
What is STIX?
Structured Threat Information Expression - threat intelligence expressed in JSON format
What is TAXII?
Trusted Automated eXchange of Intelligence Information - the HTTPS-based method for transferring STIX information.