5.0 Risk Management Flashcards
An agreement that specifies what type of business partnership two entities will have; often this dictates other considerations, such as interconnection requirements and security.
BPA (Business Partners Agreement)
A contractual agreement, signed by an organization and a third party provider, that details level of security, data availability, and other protections afforded the organization’s data held by a third party.
SLA (service Level Agreement)
An agreement between two parties, usually either two businesses or two providers, that specifies the term of connecting their respective private network infrastructures.
ISA (Interconnection Security Agreement)
A document that defines an agreement between two parties in situations where a legal contract is not necessary or appropriate, such as where both parties work for the same overall organization.
MOU/MOA
A personal security concept that states a single individual should not perform all critical or privileged level duties.
Separation of Duties
Organizational policy that describes both acceptable and unacceptable actions when using organizational computing resources, as well as the consequences of unacceptable use.
Acceptable Use Policy
The maximum amount of time that a resource may remain unavailable before unacceptable impact on other system resources occur.
RTO (recovery Time Objective)
The maximum amount of data that can be lost for the organization, after which the business cannot recover or would suffer significant loss.
RPO (Recovery Point Objective)
A numerical value estimate for a piece of hardware or equipment that indicates how much time likely will pass between major failures of that hardware or equipment.
MTBF (Meantime Between Failure)
A numerical estimate for a piece of hardware or equipment that indicates the likely time between the point a component fails and the time it can be recovered, either through repair or replacement.
MTTR (Meantime To Recover)
A system component that has no backup, redundancy, or fault tolerance, such that if the component fails, the entire system fails.
SPOF (Single Point of Failure)
Natural disaster outside the control of humans.
Environmental Threat
Any threat that is not environmental.
Manmade
Threat that is generated by internal sources, usually an insider to the organization.
Internal
Threat generated from outside of your infrastructure.
external
The monetary value of any single loss. It is used to measure risk with ALE and ARO in quantitative risk assessment.
SLE x ARO= ____
SLE (single Loss Expectancy)
The expected loss for a year. It is used to measure risk with ARO and SLE in quantitative risk assessment.
SLE x ARO =_____
ALE (Annual Loss Expectancy)
The number of times a loss is expected to occur in a year. It is measured with risk using ALS and SLE in a quantitative risk assessment.
ARO (annualized rate of occurrence)
An element of risk assessment. It identifies the value of an asset and can include any product, system, resource, or process. The value can be a specific monetary value or subjective value.
Asset Value
A document listing information about risks. It typically includes risk scores along with recommended security controls to reduce the risk scores.
Risk Register
A risk assessment that uses specific monetary amounts to identify cost and asset value. It then uses SLE and ARO to calculate ALE.
Quantitative Risk Assessment
A risk assessment that uses judgment to categorize risks. Its based on impact and likelihood of occurrence.
Qualitive Risk Assessment
A strategy of dealing with risk in which it is decided the best approach is simply to accept the consequences should the threat happen.
Risk Acceptance