Risk Management Flashcards

(30 cards)

1
Q

Risk Assessment

A

Identifies and triages risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat

A

External forces that jeopardize security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat vector

A

Methods used by attacker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerabilities

A

Weaknesses in your security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Likelihood

A

Probability risk will occur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Impact

A

Amount of damage that will occur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Qualitative techniques

A

Subjective rating to evaluate risk likelihood and impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Quantitative techniques

A

Numerical ratings to evaluate risk likelihood and impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Risk treatment

A

Analyzes and implements responses to control risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk avoidance

A

Change business practices to make a risk irrelevant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk transference

A

Shift the risk from your organization to another organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk mitigation

A

Reduces the likelihood or impact of a risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Risk acceptance

A

Choice to continue operations in the face of risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Risk profile

A

Set of risks an organization faces

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Inherent risk

A

Initial level of risk that exists in the organization before any controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Residual risk

A

Risk left after controls are implemented

17
Q

Control risk

A

New risks from adding controls

18
Q

Risk tolerance

A

Level of risk organizations will accept

19
Q

Security controls

A

Reduce the likelihood or impact of a risk and help identify issues

20
Q

Control purpose

A

Preventative
Detective
Corrective

21
Q

Control mechanism

A

Technical
Administrative
Physical

22
Q

Preventative controls

A

Stop a security issue from occurring e.g. firewall

23
Q

Detective controls

A

Identify security issues requiring investigation e.g. IPS, antivirus

24
Q

Recovery controls

A

Remediate security issues that have occurred e.g. restoring from backup

25
Technical (logical) controls
Use of technology to achieve control objectives e.g. firewall, antivirus
26
Administrative controls
Use of processes to achieve control objectives e.g. user access reviews, logs
27
Physical controls
Impact the physical world e.g. locks, cameras, guards
28
Configuration management
The way devices are setup: OS and software
29
Baseline
A snapshot of a system or app at a given time. Can we used to assess for unauthorized changes
30
Versioning
Assign numbers to each release of a piece of software.