Chapter 6 Flashcards

(10 cards)

1
Q

What are the steps of Defensive Programming?

A
  • Identify: capture likelihood and impact
  • Analyze: assess using risk score
  • Treat: Choose to remove, control, anticipate, accept, or transfer risk
  • Design Defensively
  • Evaluation: Re-assess risks again
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why are Metrics Important in Risk Assessment?

A

They turn claims into evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How Does One Control the Impact of a Risk?

A

Impact only drops if the control limits the consequences when failure occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How are Risks Primarily Affected in Risk Management?

A

The likelihood is always affected but the damage is usually the same

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the Risk Levels in Risk Assessments?

A
  • High: 15-25
  • Medium: 7-14
  • Low: 1-6
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the Risk Treatment Options?

A
  • Avoid/Eliminate: remove risk
  • Control/Reduce/Mitigate: control likelihood
  • Detect/Respond/Recover: anticipate risk
  • Transfer/Share: pass risk
  • Assume/Accept/Retain: acknowledge and accept risk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Preferred Treatment for High Risk Threats?

A
  • Avoid/Eliminate, Mitigate/Control
  • Add a Detect/Recover if severe impact
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Preferred Treatment for Medium Risk Threats?

A

Control/Mitigate, Detect/Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Preferred Treatment for Low Risk Threats?

A

Accept/Transfer with monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why Would an Organization Assume/Accept/Retain a Risk?

A
  • The impact is low
  • The cost of mitigation is higher than the risk itself
How well did you know this?
1
Not at all
2
3
4
5
Perfectly