4.1 - Describe the properties of a Security Case for a known system. Flashcards
How do OWASP define risk?
OWASP classifies it as Risk = Likelihood * Impact
What is Risk Avoidance
Eliminate. - Informed decision not to be involved in, or to withdraw from, an
activity in order not to be exposed to a particular risk (ISO Guide 73)
What is Risk acceptance
The business will accept the risk with its impact and probability since the risk could be small or unlikely.
Name risk probabilities
very likely, likely and unlikely
Risk Transference
This is transferring or sharing the risk with a third party
What is risk? (as defined in ISO 27000)
Risk. The effect of uncertainty on objectives (ISO/IEC 27000)
What is Risk Reduction
Action taken to lessen the probability, negative consequences, or
both, associated with risk (ISO 22300:2018) - Could also be refereed to as mitigation
What is a security business case?
It can be used to justify reasoning behind a security decision/security solution being bought.
What is important in a security business case
Well researched.
What is the value of a security business case to a security professional?
Transfer responsibility to management.