Basic Risk Concepts Flashcards
What is the definition of a Threat?
is any circumstance or event that has the potential
to compromise confidentiality, integrity, or availability.
Risk is the possibility or likelihood of…
threat exploiting a vulnerability
resulting in a loss
What are the 3 types of controls that describe HOW the control is implemented?
Technical, Administrative and Physical
organizational policies and guidelines are used to implement what kind of control?
administrative controls
operational controls, which are a form of admin control, ensure the day-to-day operations of an organization comply with the org’s overall security plan - true or false?
True
Account disablement, security guards and hardening are examples of what type of control?
Preventative
backup and system recovery is a type of what control?
Corrective. Because it reverses the data loss
what control is an alternative control used instead of a primary control?
compensating control
What are the 4 control types that describe the GOAL of the control
Deterrent
Detective
Corrective
Preventative