Chapter 1 - Measuring and Weighing Risk Flashcards
Rene
What is the Risk Calculator?
page 5.
SLE x ARO = ALE =>(AV x EF) x ARO = ALE
ALE = Annual Loss Expectancy, measures how much loss you could expect in a year.
ARO = Annualized Rate of Occurance
SLE = Single Loss Expectancy, represents how much you expect to lose at any one time.
AV - Asset Value
EF = Exposure Factor
Rene
What are Threat Vectors?
page 8.
Is the way in which an attacker poses a threat.
Can be anything from a fake email that lures you into clicking (phishing) or an unsecure hotstop.
Rene
What is the measure of the anticipated incident of failures for a system or component?
page 8
Mean Time Between Failures (MTBF)
Rene
What is Risk Assessment?
page 3
Deals with the threats, vulnerabilities and impacts of a loss of information-processing capabilities or a loss of information itself.
Rene
What is the best way to explain quantitative and qualitative?
page 7
Quantitative - think of the goal as determining a dollar amount
Qualitative - think of a best guess or opinion of the loss, including reputation, goodwill and irreplaceable information, pictures or data that get you to a subjective loss amount.
Rene
What is the average time to failure for a non-repairable system?
page 8
Mean Time to Failure (MTTF)
Rene
What involves identifying a Risk and making the decision not to engage any longer the actions associated with that risk?
page 9
Risk Avoidance
Rene
What is the maximum amount of time that a process or service is allowed to be down and the consequences still be considered acceptable?
page 9
Recovery Time Objective (RTO)
Rene
What does not imply to shift the risk completely to another entity?
page 9
Risk Transference
The burden of the risk is shared with someone else, such as an insurance company.
Rene
What is similar to RTO, but it defines the point at which the system needs to be restored?
page 9
Recovery Point Objective (RPO)
Rene
How is Risk Mitigation Achieved?
page 9 Anytime you take steps to reduce risk. * antivirus software * educating users * monitoring network traffic * adding firewall
Rene
What is the measure of how long it takes to repair a system or component once a failure occurs?
page 8
Mean Time to Restore (MTTR)
Rene
What can posting prosecution policies on your login pages and convincing them that you have steps in place to ID intrusions and act on them?
page 10
Risk Deterrence
Rene
When you choose not to implement any prevention of risk due to costs and accept the potential costs or damage and agree to accept it.
page 10
Risk Acceptance
Rene
What is cloud computing and examples?
page 17
Hosts services and data on the Internet instead of hosting it locally.
Office 365, Google Docs
Google Drive, Sky Drive, Amazon Web Services