Domain 1: Information Security Governance and Risk Management Flashcards
(150 cards)
What does the acronym ALE stand for ?
Annual Loss Expectancy
What does Annual Loss Expectancy (ALE) mean?
Allows security practitioners to determine the annual cost of a loss due to risk.
What is the Annual Loss Expectancy (ALE) Formula?
Single Loss Expectancy (SLE) X Annual Rate of Occurrence (ARO)
What does the Annual Rate of Occurrence (ARO) mean?
The number of losses you suffer per year
What does the acronym ARO stand for?
Annual Rate of Occurrence
What does the phrase
Exposure Factor (EF)
mean in the Annual Loss Expectancy section?
The Percentage of value an Asset lost due to an incident.
What does Asset Value (AV) mean?
The value of an asset you are trying to protect.
What does ROI stand for?
Return on Investment
What does the acronym EF stand for in the Annual Loss Expectancy section?
Exposure Factor
What does the phrase
Single Loss Expectancy (SLE)
mean in the Annual Loss Expectancy (ALE) section?
The cost of a single Loss.
What does the acronym
SLE
stand for?
Single Loss Expectancy
What is the
Single LossExpectancy (SLE)
Formula?
SLE = AV * EF
What does the phrase
Return on Investment (ROI)
mean?
The amount of money saved by implementing a safguard
What component can you add to the a
Risk Calculation
to give it more meaning?
Add Impact to the equation: Risk = Threat * Vulnerability * Impact
What does AV stand for in the Annual Loss Expectancy framework?
Asset Value
What does
Total Cost of Ownership (TCO)
mean?
The total cost of a mitigated safeguard
What does the acronym
TCO
stand for?
Total Cost of Ownership
What is the
Single Loss Expectancy (SLE)
Formula?
Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF)
Can a certification be performed by a trusted third party?
Yes
Who accepts the risk in an Accreditation?
The Data Owner
What is a certification?
A detailed inspection that verifies whether a system meets the documented security requirements.
When a certification is performed by a trusted third party, are the issues identified recommendations
or
mandatory
actions?
Recommendations
What is an Accreditation?
The Data Owner’s acceptance of the risk represented by the system.
What are NIST’s four steps to accreditation?
1: Initiation Phase (Research)
2: Security Certification Phase (Assessment)
3: Security Accreditation Phase (Decision to Accept Risk)
4: Continuous Monitoring Phase (Monitor)