(8) Risk and Risk Assessments Flashcards

1
Q

What is the formula for risk severity?

A

Risk Severity = Probability x Magnitude

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is risk avoidance?

A

Risk avoidance is where a business chooses to totally eliminate the chance that a risk will happen, such as shutting down a website completely, which is too harsh of course

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is risk transferrence?

A

Risk transference is about shifting some of the impact of the risk to another entity, such as through getting cyber security insurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is risk acceptance?

A

Risk acceptance is where the risk is accepted and nothing is done. This is useful if the cost of taking care of the risk is more expensive than if the risk actually happens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is risk mitigation?

A

Risk mitigation is putting something in place to reduce the risk, such as by using multi factor authentication in order to reduce the chance of an account takeover by way of a password crack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are technical controls?

A

Technical controls operate in the confidentiality, integrity, and availability in the digital side of things, such as through firewalls, ACLs, IPSs, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are operational controls?

A

Operational controls include the processes that are put in place to manage tech in a secure way.

This can involve user access reviews, log management, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are Managerial controls?

A

Managerial controls are those that pay attention to the mechanics of the risk management flow. These could involve performing risk assessments, security exercises, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly