Risk Management Flashcards

(33 cards)

1
Q

BIA

A

Business Impact Analysis

Evaluates effects of disruptions on business functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RPO

A

Recovery Point Objective

○ Maximum acceptable data loss measured in time
○ Point in time data must be restored to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

MTTR

A

Mean Time To Repair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

MTBF

A

Mean Time Between Failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Register

A

Records identified risks, descriptions, impacts, likelihoods, and mitigation actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk Tolerance/Risk Appetitie

A

Willingness to pursue or retain risk.

Expansionary, Conservative or Neutral

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

KRIs

A

Key Risk Indicators

Predictive metrics signaling increasing risk exposure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk Owner

A

Responsible for managing the risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Qualitative Risk Analysis

A

Assesses risk based on potential impact and likelihood. Subjective and relies on expertise and experience

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quantitative Risk Analysis

A

Provides objective and numerical evaluation of risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

EF

A

Exposure Factor

Proportion of asset lost in an event (0-100%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SLE

A

Single-Loss Expectancy

Monetary value expected to be lost in a single event.

Asset Value x Exposure Factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ARO

A

Annualized Rate of Occurrence

Estimated yearly frequency of risk incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ALE

A

Expected annual loss from a risk

SLE x ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Risk Transference

A

Shift risk to another party (insurance, contract idemnity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk Acceptance

A

Acknowledge and deal with risk if it occurs.

Used when managing the risk outweighs potential loss

17
Q

Risk Avoidance

A

Change plan or strategy to eliminate a risk

Chosen when the risk is too great to accept or transfer

18
Q

Risk Mitigation

A

Take steps to reduce likelihood or impact of risk

19
Q

Residual Risk

A

Likelihood after mitigation, transference or acceptence

20
Q

Control Risk

A

Assessment of how a security measure has lost effectiveness over time

21
Q

CHIPS Act of 2022

A

■ U.S. federal statute providing funding to boost semiconductor research and
manufacturing in the U.S.
■ Aims to reduce reliance on foreign-made semiconductors, strengthen the domestic supply chain, and enhance security

22
Q

MSP

A

Managed Service Provider

Manage IT services on behalf of organizations

23
Q

Right-to-Audit clause

A

Contract provision allowing organizations to evaluate vendor’s internal processes
for compliance

24
Q

Vendor Questionnaire

A

Comprehensive documents filled out by potential vendors

Provide insights into operations, capabilities, and
compliance

25
Rules of Engagement
Guidelines for interaction between organization and vendors
26
Vendor Monitoring
Mechanism used to ensure that the chosen vendor still aligns with organizational needs and standards
27
SLA
Service Level Agreement Defines the standard of service a client can expect from a provider. Includes performance benchmarks and penalties for deviations
28
MOA
Memorandum of Agreement Formal, outlines specific responsibilities and controls
29
MOU
Memorandum of Understanding Less binding than MOA. Expresses mutual intent without specifics.
30
MSA
Master Service Agreement Covers general terms of engagement across multiple transactions
31
SOW
Statement of Work Specifies project details, deliverables, timelines, and milestones. Provides in-depth project-related information
32
NDA
Non-Disclosure Agreement Ensures confidentiality of sensitive information shared during negotiations
33
BPA or JVA
Business Partnership Agreement or Joint Venture Agreement ● Goes beyond basic contracts when two entities collaborate ● Outlines partnership nature, profit-sharing, decision-making, and exit strategies ● Defines ownership of intellectual property and revenue distribution