5.4 Risk Management Flashcards
SSO
Single Sign-On is convenient for users since they only need to remember one set of credentials. Unfortunately, single sign-on also introduces a single point of failure. If the identity provider is offline, then the user cannot log in to any of the resources they may wish to utilize across the web. Additionally, if the single sign-on is compromised, the attacker now has access to every site that the user would have access to using the single set of credentials
Risk appetite
ow much risk an organization is willing to accept. This is a crucial factor both in designing the assessment and determining the recommended mitigations
Risk mitigation
strategy to prepare for and lessen the effects of threats faced by a data center. Risk mitigation refers to applying security controls to reduce the risk of a known vulnerability
Risk avoidance
elimination of hazards, activities, and exposures that can negatively affect an organization’s assets
Risk acceptance
act of accepting the identified risk and not taking additional actions to reduce the risk because the risk is low enough. Risk acceptance should only be done once an organization’s risk tolerance is defined and communicated amongst the decision-makers
Mission Essential Function
things that must be performed by an organization to meet its mission. For example, the Army being able to deploy its soldiers is a mission-essential function
critical system
For example, the Army being able to deploy its soldiers is a mission-essential function. If they couldn’t do that because a network server is offline, then that system would be considered a critical system and should be prioritized for higher security and better defenses