10: 1 Risk Analysis Flashcards

1
Q

Risk Assessment

A

Identifying and triaging the risks facing an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat

A

External force that jeopardizes security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat vector

A

Method an actor uses to get to their target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerability

A

Weakness in security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk

A

Combination of vulnerability and a corresponding threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Factors that prioritize a risk

A

Likelihood and Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Qualitativee Risk Assessment

A

Use subjective ratings to evaluate risk (Low, medium, high)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Quantitative Risk Assessment

A

Uses objective numeric ratings to evaluate risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Quantitative Risk Assessment is performed on?

A

Single risk and asset pair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AV

A

Asset value - the dollar value of an asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AV Techniques (3)

A

Original Cost Technique
Depreciated Cost Technique
Replacement Cost Technique

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

EF

A

Exposure Factor- Expected percentage of damage to an asset (%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SLE

A

Single-Loss Expectancy - Expected dollar loss if a risk occurs one time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Formula for SLE

A

SLE = AV * EF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ARO

A

Annualized Rate of Occurrence- Number of times a risk is expected to occur each year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ALE

A

Annualized Loss Expectancy - Expected dollar loss from a risk in any given year

17
Q

Formula for ALE

A

ALE = SLE * ARO

18
Q

MTTF

A

Mean Time to Failure - Average time a nonrepairable assets will last

19
Q

MTBF

A

Mean Time Between Failures - Average time between failures of a repairable asset

20
Q

MTTR

A

Meant Time to Repair - Average time required to return a repairable component to service

21
Q

Internal Risk

A

Arise from within the organization

22
Q

Address Internal Risks?

A

Using internal controls

23
Q

External Risk

A

Arise from outside the organization

24
Q

Address External Risks?

A

Using internal controls

25
Q

Multiparty Risks

A

Shared across many organizations (i.e. software as a service provider is compromised)

26
Q

Legacy Risks

A

Arise from unsupportable systems

27
Q

Software license compliance issues

A

Risk of fines and legal action

28
Q

Data Classification Policies

A

Assign information into categories that determine storage, handling, and access requirements

29
Q

Assign classification based upon

A

Sensitivity of Information, Criticality of Information

30
Q

Types of Sensitive Customer Information

A

PII, Financial Information, Healthcare Information (HIPAA)