Risk Analysis And Review Flashcards

0
Q

Define risk

A

Potential loss exposure due to a threat, causing disruptions to business operations and preventing them from achieving minimum business continuity objective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

Define risk analysis

A
  • subset of risk assessment

* process to identify risks, define controls to reduce exposure and evaluate cost for controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain and provide examples of threats

A

An indication or warning of man made or natural situation that causes disruption to an organization’s operations or services.

Threats consist of natural phenomena (I.e. Earthquake and tornadoes) and man made incidents (I.e. Terrorism and power failures)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the four risk treatments?

A

Risk transference, risk reduction, risk acceptance and risk avoidance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define control

A

Action, procedure or operation undertaken to increase likelihood that activities, policies and procedures can contain risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe and give control measures for RISK AVOIDANCE

A

Makes an informed decision not to become involved in or to withdraw from a risk situation.

Control measures:
• change process
• move location
• takeover supplier or customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe and give control measures for RISK REDUCTION

A

Take appropriate actions to lessen probability, negative consequences or both.

Control measures:
• Security protection - physical protection
• logical protection - info backup and protection, info security
• procedurals protection - develop procedures to reduce operator error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define and give control measures for RISK TRANSFERENCE

A

Passing of responsibility to another party through legislation, contract, insurance or other means.

Control measures:
• outsource
• insurance
• penalty clauses
• service level agreements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define and give examples of RISK ACCEPTANCE

A

Make informed decision to accept probability and impact of risk.

Examples: inherent risks, unlikely events, beyond control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Key disaster scenario

A
  • address multiple threats
  • provides bc team with perspective of magnitude of disaster
  • based on list of threats identified
How well did you know this?
1
Not at all
2
3
4
5
Perfectly