Risk Management Flashcards
(71 cards)
What is the purpose of the document?
To provide an overview of risk management standards, methodologies, and tools, and to support EU institutions in addressing gaps in risk management.
Which EU institution facilitates the establishment of risk management standards?
ENISA (European Union Agency for Cybersecurity).
What is the NIS Directive?
The Network and Information Security Directive (Directive 2016/1148) that sets legal obligations for ICT security in the EU.
How does the Cybersecurity Act define ENISA’s role?
ENISA shall facilitate the establishment and take-up of European and international standards for risk management and ICT security.
Which sectors are considered critical under the NIS Directive?
Energy, Transport, Banking, Financial market infrastructures, Health, Drinking water supply, and Digital Infrastructure.
What is risk according to ISO 31000:2018?
The effect of uncertainty on objectives.
What is risk management?
Coordinated activities to direct and control an organization with regard to risk (ISO 31000:2018).
What are the key steps in the risk management process?
Risk identification, risk analysis, risk evaluation, risk treatment, risk monitoring, and risk communication.
What is risk treatment?
The process of modifying risk, including avoiding, reducing, sharing, or accepting it.
Which regulation focuses on cybersecurity certification?
The Cybersecurity Act (Regulation (EU) 2019/881).
What is ISO/IEC 27005?
A standard providing guidelines for information security risk management.
Which ISO standard provides general guidelines for risk management?
ISO 31000:2018.
What is the role of risk management in cybersecurity?
To protect valuable assets, evaluate security threats, prevent fraud, and ensure business continuity.
What are the risk treatment options according to ISO 31000?
Avoiding, taking/increasing, mitigating, sharing, or retaining the risk.
What is NIST 800-30?
A risk management guide developed by NIST for assessing and mitigating risks in IT systems.
What does the GDPR regulate?
It governs data protection and privacy for individuals in the EU (Regulation (EU) 2016/679).
What is the purpose of risk assessment?
To identify and evaluate risks and prioritize them for treatment.
What is the difference between risk assessment and risk treatment?
Risk assessment identifies and evaluates risks, while risk treatment focuses on reducing or mitigating them.
What are the components of risk analysis?
Threat identification, likelihood estimation, and impact assessment.
What does the OCTAVE methodology focus on?
Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) is a self-directed risk evaluation method.
What is CRAMM?
A methodology for evaluating security risks by analyzing corporate environments.
What does the MEHARI method focus on?
A qualitative risk management approach developed by CLUSIF in France.
What is the primary purpose of the Cybersecurity Act?
To establish cybersecurity certification frameworks and risk management standards in the EU.
What is IT-Grundschutz?
A risk assessment framework developed by the German BSI for IT security management.