(8) Risk and Risk Assessments Flashcards
What is the formula for risk severity?
Risk Severity = Probability x Magnitude
What is risk avoidance?
Risk avoidance is where a business chooses to totally eliminate the chance that a risk will happen, such as shutting down a website completely, which is too harsh of course
What is risk transferrence?
Risk transference is about shifting some of the impact of the risk to another entity, such as through getting cyber security insurance
What is risk acceptance?
Risk acceptance is where the risk is accepted and nothing is done. This is useful if the cost of taking care of the risk is more expensive than if the risk actually happens
What is risk mitigation?
Risk mitigation is putting something in place to reduce the risk, such as by using multi factor authentication in order to reduce the chance of an account takeover by way of a password crack
What are technical controls?
Technical controls operate in the confidentiality, integrity, and availability in the digital side of things, such as through firewalls, ACLs, IPSs, etc.
What are operational controls?
Operational controls include the processes that are put in place to manage tech in a secure way.
This can involve user access reviews, log management, etc.
What are Managerial controls?
Managerial controls are those that pay attention to the mechanics of the risk management flow. These could involve performing risk assessments, security exercises, etc.