Risk Management Flashcards

(45 cards)

1
Q

WHAT IS RISK MANAMENT

A

KEEP UP WITH RISK BY LOOKING REPORTING PATCHING ETC.
`\

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RISK ANALYSIS

A

LIST OF RISK THAT CAN HELP YOU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

RISK TREATMENT

A

HELP MANAGING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

RISK ASSESSMENT FREQUENCE

A

HOW OFTEN THE RISK ASSESSMENT IS CONDUCTED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AD-HOC

A

CONDUCTED WHEN AND AS NEEDED TO A SPECIFIC EVENT THAT CAN INTRODUCE NEW RISK OR CHANGE. NATRUAL DIASTER

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

RECURRING RISK ASSESSMENT

A

MONTHLY,ANNUALLY OR QUARTERLY ANALYSIS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ONE TIME RISK ASSESSMENT

A

NOT REPEATED FOR PROJECTS OR USING NEW IT SYSTEMS JUST HAPPENS ONE TIME.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CONTINUOUS RISK ASSESSMENTS

A

ON GOING MONITOR AND EVAL ON RISK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RISK IDENTIFICIATION

A

RECOGNIZING POTENITAL RISK THAT COULD IMPACT ORG’S

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

BUSINESS IMPACT ANALYSIS

A

EVALUATING POTENTIAL EFFECTS OF DISRUPTION TO AN ORG BUSINESS FUNCTIONS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

RTO-RECOVERY TIME OBJECTIVE

A

REPRESENTS THE MAX ACCEPTABLE LENGTH OF TIME. BEFORE THE LACK OF A BUSINESS FUNCTION GETS REALLY IMPACTED.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RECOVERY POINT OBJECTIVE-RPO

A

MAX ACCEPTABLE AMOUNT OF DATA LOSS IN MEASURED TIME.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

MTTR MEAN TIME TO REPAIR-MMTR

A

AVERAGE TIME REQUIRED TO REPAIR A FAILED COMPONENT OR SYSTEM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

MEANT TIME BETWEEN FAILURES MTBF

A

AVERAGE TIME BETWEEN FAILURES.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

RISK REGISTER

A

A DOCUMENT RECORDS DEATILS OF THE RISK SUCH AS WHAT AND HOW IT HAPPENED.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

RISK DESCRIPTION

A

DEATILING WHAT THE RISK IS DESCRIPTION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

RISK IMPACT

A

THE CONSEQUENCES IF THE RISK TAKES PLACE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

RISK LIKELIHOOD

A

CHANCE OF THE RISK HAPPENING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

RISK OUTCOME

A

IF RISK HAPPENS WHAT IS THE RESULT OF IT

20
Q

RISK LEVEL

A

COMBINING IMPACT AND LIKELIHOOD

21
Q

THE COST OF RISK

A

COST OF MITAGTING/HAPPENING RISK.

22
Q

RISK TOLERANCE

A

THE ORG IS WILLING TO ACCEPT THE RISK

23
Q

RISK APPETITIE

A

AN ORG WILLING TO EMBRACE SPECIFIC TYPES OF RISK.

24
Q

EXPANSIONARY RISK APPETITIE

A

ORG IS TAKING MORE RISK TO GETTER LARGER RETURNS

25
CONSERVATIVE RISK APPETITIE
FAVORS LESS RISK
26
NEUTRAL RISK APPETITITE
BALANCE OF RISK AND RETURN.
27
KEY RISK INDICATORS
PREDICTIVE METRICS TO SIGNAL RISING RISK LEVELS IN DIFFERENT PARTS OF THE ENTERPRISE.
28
RISK OWNER
PERSON OR GROUP IN CHARGE OF TAKING RESPOINIBTY OF THE RISK
29
QUALTIVITE RISK ANALAYSIS
METHOD OF ASSESSING RISK BASED ON THE IMPACT AND LIKELIHOOD OF THEM HAPPENING.
30
EXPOSURE FACTOR
PROPORTION OF AN ASSET THAT IS LOST.
31
SINGLE LOSS EXPECTANCTY SLE
MONETERY VALUE EXPECTED TO BE LOST IN A SINGLE EVENT
32
ANNUALIZED RATE OF OCCURRENCE
ESTIMATED FREQUENCY WITH WHICH A THREAT IS EXPECTED TO OCCUR IN A YEAR.
33
ANNUALIZED LOSS EXPECTANCY
SLE x ARO annual lost from a risk
34
RISK MANAGMENT STRATS
-RISK TRANSFERENCE SHIFTING RISK TO ANOTHER PARTY -RISK ACCEPTANCE- DEALING WITH A RISK IF IT OCCURS BASICALLY WHEN IT ARISES. -EXEMPTION- EXCLUDES PARTY FROM A SPECIFIC RULE OR REQUIRMENT. EXCEPTION- PERMITS PARTY TO BY PASS A RULE OR REQUIRMENT.
35
RISK AVOIDANCE
PLANS TO COMPLETELY AVOID THE RISK
36
RISK MITIGATION
STEPS TO TAKE TO DECRESE LIKELIHOOD THE RISK.
37
RISK MONITORING
TRACKING IDENTIFIED ASSESSING EXECUTING RESPONSE ACTION ON A RISK
38
RESIDUAL RISK
IMPACT AFTER IMPLMENTNG MITAGAION
39
CONTROL RISK
HAS LOST EFFECTIVENESS OVER TIME.
40
RISK REPORTING
COMMUNICATION INFO ABOUT RISK MANAGEMENT ACTIVITIES.
41
INFORMED DECISION MAKING
INSIGHTS FOR INFORMED DECISIONS ON RESORVCE ALLOACATIONI
42
RISK MITIGATION
WHEN A RISK ESCLATIONG TO MITIAGETE THE RISK BEFORE IT BECOMES A PROBLEM
43
STAKEHOLDER COMM
SETTING EXPECTIONS AND SHOWING EFFECTIVE RISK MANANGMENT
44
REGULATORY COMPLIANCE
???
45
SLE
The Single Loss Expectancy (SLE) is calculated as the value of the asset multiplied by the Exposure Factor (EF). In this case, SLE =12,000. The Annualized Rate of Occurrence (ARO) is 1/5 (since the server crashes once every five years) = 0.2. The Annualized Loss Expectancy (ALE) is calculated as SLE * ARO. In this case, ALE= 12,000 * 0.2= 2,400.