4.1 - Describe the properties of a Security Case for a known system. Flashcards

1
Q

How do OWASP define risk?

A

OWASP classifies it as Risk = Likelihood * Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Risk Avoidance

A

Eliminate. - Informed decision not to be involved in, or to withdraw from, an
activity in order not to be exposed to a particular risk (ISO Guide 73)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Risk acceptance

A

The business will accept the risk with its impact and probability since the risk could be small or unlikely.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name risk probabilities

A

very likely, likely and unlikely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Transference

A

This is transferring or sharing the risk with a third party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is risk? (as defined in ISO 27000)

A

Risk. The effect of uncertainty on objectives (ISO/IEC 27000)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Risk Reduction

A

Action taken to lessen the probability, negative consequences, or
both, associated with risk (ISO 22300:2018) - Could also be refereed to as mitigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a security business case?

A

It can be used to justify reasoning behind a security decision/security solution being bought.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is important in a security business case

A

Well researched.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the value of a security business case to a security professional?

A

Transfer responsibility to management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly