Primary Definitions 8.0-13.0 Flashcards
Understanding the core security concepts. (144 cards)
Risk Management
Fundamental process that involves identifying, analyzing, treating, monitoring, and reporting risks.
Risk Assessment Frequency
The regularity with which risk assessments are conducted within an organization.
Risk Identification
Recognizing potential risks that could negatively impact an organization’s ability to operate or achieve its objectives.
Business Impact Analysis
Process that involves evaluating the potential effects of disruption to an organization’s business functions and processes.
Recovery Time Objective (RTO)
It represents the maximum acceptable length of time that can elapse before the lack of a business function severely impacts the organization.
Recovery Point Objective (RPO)
It represents the maximum acceptable amount of data loss measured in time.
Mean Time to Repair (MTTR)
It represents the average time required to repair a failed component or system.
Mean Time Between Failures (MTBF)
It represents the average time between failures.
Risk Register (Risk Log)
A document detailing identified risks, including their description, impact likelihood, and mitigation strategies.
Risk Tolerance/Risk Acceptance
Refers to an organization or individual’s willingness to deal with uncertainty in pursuit of their goals.
Risk Appetite
Signifies an organization’s willingness to embrace or retain specific types and levels of risk to fulfill its strategic goals.
Key Risk Indicators (KRIs)
Essential predictive metrics used by organizations to signal rising risk levels in different parts of the enterprise.
Risk Owner
Person or group responsible for managing the risk.
Qualitative Risk Analysis
A method of assessing risks based on their potential impact and the likelihood of their occurrence.
Quantitative Risk Analysis
Method of evaluating risk that uses numerical measurements.
Single Loss Expectancy (SLE)
Monetary value expected to be lost in a single event. Calculated by multiplying the value of the asset by the exposure factor
Annualized Rate of Occurrence (ARO)
Estimate frequency with which a threat is expected to occur within a year.
Annualized Loss Expectancy (ALE)
Expected annual loss from a risk (SLE x ARO).
Exposure Factor (EF)
Proportion of an asset that is lost in an event. Expressed as percentage 0% is no loss 100% is total loss.
Risk Transference (Risk Sharing)
Involves shifting the risk from the organization to another party.
Risk Acceptance
Recognizing a risk and choosing to address it when it arises.
Risk Avoidance
Strategy of altering plans or approaches to eliminate a specific risk.
Risk Mitigation
Implementing measures to decrease the likelihood or impact of a risk.
Risk Monitoring
Involves continuously tracking identified risks, assessing new risks, executing response plans, and evaluating their effectiveness during a project’s lifecycle.