Cards 41-80 Flashcards

1
Q
  1. Two reasons to collect physical security program metrics:

-provide assurance of p____ e____; and
-f________ imp________.

A

Program effectiveness

Facilitate improvements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  1. Commonly provides management with a snapshot of the effectiveness and efficiency of a physical security program?

-A m_______ S______ chart

A

A metrics summary chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
  1. The purpose of a business impact analysis (BIA)?

ID and ev______ the potential impact of a dis______ ev_____ to operations.

A

Evaluate;

Disruptive event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The purpose of a business continuity management system (BCMS)….?

-enable a company to address potentially d_____ ev______ by identifying, developing and implementing P___, ob ___, cap____, p_____ and Pro_____ w/in legal bounds.

A

Disruptive events;

Policies;
Objectives;
Capabilities;
Processes & programs…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  1. What two things are the foundation for setting up business continuity o__, t___, pr___ and pl___?

-The B___I____a____ and the R__A___

A

Objectives, targets, programs and plans;

The business impact analysis and the risk assessment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  1. Name 3 inter-related management response steps that require pre-emptive planning and implementation in case of a disruptive or crisis event?

-e____r____;
-c_____ and
-r______

A

Emergency response;

Continuity planning; and

Recovery planning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  1. What is the basis for setting recovery time objectives?

-The results of the b___IM____A___

A

Business impact analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
  1. What is a disruptive event?

An event that is planned or not planned that interrupts a___o____ or f______

A

Activities;

Operations; or

Functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  1. What is a threat?

-The p___ c____ of an unwanted incident which may harm

I____
A____
A sys____
An org____
The e_____ or
The c_____

A

Potential cause

Individuals;
Assets;
A system
An organization
The environment or
The community

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

50.What is a loss event profile?

-a list of the k____ of th______ affecting the a______to be safeguarded.

A

Kind of threats

Assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
  1. What is a hazard?

A source of p____d____ or ad___ c____. They are generally associated with n_______

A

Potential danger

Adverse condition

Nature

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  1. Threats or loss risk events fall into three categories:

-C______
-non-criminal man-made in__ or N___ d____
- events caused by an org’s r_____ with other orgs

A

Crimes;

Incidents or natural disasters

Relationship

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. Examples of non-criminal threats?

-N___threats - h__, t___, s___
-M___ M___ threats/disasters - plane crash, l____ s_____, power failure

A

Natural threats - hurricane, tornado, storm;

Man-made….labor strike

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
  1. Examples of peripheral systems and interfaces?

-L____ S_____ systems;
-B_____ controls;
-IT i________
- L_____r______
-O______ S______ and
-P_____ and pr______

A

Life safety;
Building controls;
Infrastructure;
Liaison relationships
Outsourced services;
Policies & procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
  1. What is a consequential event?

-An event that occurs b/c a relationship between e____ or between two o_____. The company suffers a loss b/c of that event or relationship.

A

Events

Organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  1. How is the probability of a threat occurring decided?

-by considering the likelihood that a l____ r_____ e_____ may occur in the future.

A

Loss risk event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q
  1. What factors determine the probability of a threat?

-h______d_____;
-history of s____e____ at s___ c__
-the n____ and v_____;
-geo_____ l_____;
-po_____ and so____ conditions;
-c________ in the economy.

A

Historical data;
Similar events at similar companies
Neighborhood and vicinity
Geographical location
Politicial and social conditions
Changes in the economy

18
Q
  1. What is a vulnerability?

Any w_______ that can be exploited by an aggressor/t____ or cr_____ that makes an asset susceptible to damage from n___h____ or c____ events.

A

Weakness
/terrorist or criminal
Natural hazards or consequential events.

19
Q
  1. Factors to consider in assessing asset vulnerability?

-lack of b_____;
-single point of f______;
- co-location of k___ systems;
- inadequate r___ c____ from attacks
-Ease of aggressor a___ to a facility;
-inadequate s____ m____;
-presence of ha_____ ma_____;
-potential for collateral d___ from other companies.

A

Backup;
Failure;
Key;
Response capability;
Access;
Security measures;
Hazardous materials;
Damage

20
Q
  1. Four levels of risk?
A

Catastrophic;
High’
Moderate; and
Low

21
Q
  1. What level of risk requires treatment at any cost?
A

Catastrophic

22
Q
  1. The level of risk that cannot be further reduced w/o an expenditure of costs d_____ to b_____?
A

Disproportionate to benefits

High

23
Q
  1. The level of risk that is negligible or can be managed with routine procedures?
A

Moderate

24
Q
  1. The level of risk where the org is prepared to p___ /r____ or take based on informed decisions?
A

Pursue/retain

Low

25
Q
  1. What should occur in relation to a regular review of the physical security assessment report?

-Mo_____ and follow up on the as____ findings, ob_____ and rec_____

A

Monitor and

Assessment…

Observations

Recommendations

26
Q
  1. Two categories of threats?

Ma______ threats &
Na______ threats

A

Man-made threats and

Natural threats

27
Q
  1. This metric measures external dependencies responsiveness in meeting a security department request?

-ex_____de_____re_____

A

External dependency responsiveness

28
Q
  1. Physical security design attributes include:

-type of ad_____
-time required for an adversary to get to inside as_____;
-# and type of de_____inside and outside a facility;
-de_____ that slow down the attack; and
- Si___, st____ and Eq___ of the response force

A

Adversary;
Assets
Detectors
Delays
Size, strength and equipment

29
Q
  1. Risk assessment is….?

-The ov_____ and sy_____ process for evaluating the effects of un____on achieving an en_____ ob_______

A

Overall and systematic

Uncertainty

Enterprise’s objectives.

30
Q
  1. The goal of a cost benefit analysis?

-To id_____ the op____ levels of risk reduction at the best available va______

A

Identify the optimum

Value

31
Q
  1. The analysis method that uses comparative values and not numbers?
A

Qualitative

32
Q
  1. An analysis method that uses numeric measures to describe value of assets, level of threats, vulnerabilities, impact or loss events?
A

Quantitative

33
Q
  1. Qualitative analysis is most suited to …..?

-evaluating ba______ security applications

A

Basic

34
Q
  1. What is a SWOT analysis/

-a business analysis method that involves st____ ev_____ of key in_____ and ex_____factors.

A

Strategic evaluation

Internal and external

35
Q
  1. SWOT stands for?
A

Strengths
Weaknesses
Opportunities and
Threats

36
Q
  1. External factors in a SWOT analysis include:
A

Opportunities and threats

37
Q
  1. Internal factors in a SWOT analysis include:
A

Strengths and weaknesses

38
Q
  1. What is the annual loss expectancy?

-the product of the cost of in___ im____ and the fr____ of oc______

A

Incident impact

Frequency of occurrence

39
Q
  1. What state and local requirements should be considered for security projects?

-co_____ re____;
-tr____ and in___ best practices;
-st____;
-Pe______ re______;
-co_____ re______

A

Code regulations;
Trade and industry;
Standards;
Permitting requirements;
Contracting requirements

40
Q
  1. What conditions affect the likelihood of occurrence?

-PH……en_____;
-So____ en____;
-PO___ en____;
-Pr____ and Pr____;
-Cr____ capabilities

A

Physical environment;
Social “ “
Political. “ “
Procedures and processes;
Criminal capabilities