Chapter 1: Measuring and Weighing Risk Flashcards

1
Q

Residual Risk

A

A risk that must remain for some reason

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

BIA

A
  • Business Impact Analysis

- Outlines how to respond to various situations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Steps to Develop an Overview of Risk

A

1) Interview the department heads
2) Evaluate the network infrastructure
3) Perform a physical assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Annual Loss Expectancy (ALE)

A

A monetary measure of how much loss you could expect in a year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Single Loss Expectancy (SLE)

A

How much you expect to lose at any one time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Two components of SLE

A

1) Asset Value (AV)

2) Exposure Factor (EF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Annualized Rate of Occurrence (ARO)

A

Likelihood of an event occurring within a year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk Assessment Formula

A

SLE x ARO = ALE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Qualitative Risk Assessment

A

Opinion-based and subjective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quantitative Risk Assessment

A

Cost-based (money) and objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Likelihood

A

A score from 1-10 assessing the likelihood of an event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Threat Vector

A

The way in which an attacker poses a threat.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Mean Time Between Failures (MTBF)

A

Lifetime of a component before it must be replaced or repaired

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Mean Time To Failure (MTTF)

A

The average time to failure for a nonrepairable system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Mean Time To Restore (MTTR)

A

How long it takes to repair something once it fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Recovery Time Objective (RTO)

A

Max time that a process is allowed to be down before negative effects begin happening.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Recovery Point Objective (RPO)

A

The point the system needs to be restored to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Risk Avoidance

A

Identifying a risk and deciding to not engage in the actions associated with that risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Risk Transference

A

Share some of the burden of risk with someone else, such as an insurance company.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Risk Mitigation

A

Taking steps to reduce risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Data Loss Prevention (DLP) system

A

Makes sure key content is not removed

MyDLP

22
Q

Risk Deterrence

A

Telling attackers you’ll fuck em up if they attack you

23
Q

Platform as a Service (PaaS)

A

Vendors allow apps to be created and run on their infrastructure

24
Q

Software as a Service (SaaS)

A

Applications used over the internet, e.g. GoogleMaps

25
Q

Infrastructure as a Service (IaaS)

A

Utilizes virtualization, and clients pay an outsourcer for resources

26
Q

Scope Statement

A

What a policy intends to accomplish and which documents, laws, and practices the policy addresses.

27
Q

Policy Overview Statement

A

Provides the goal of the policy, why it’s important, and how to comply with it.

28
Q

Policy Statement

A

The actual content of the policy

29
Q

Accountability Statement

A

Who is responsible for ensuring the policy is enforced.

30
Q

Five Key Aspects to Standards Documents

A

1) Scope and Purpose
2) Roles and Responsibilities
3) Reference Documents
4) Performance Criteria
5) Maintenance and Administrative Requirements

31
Q

Four Key Aspects to Guidelines Documents

A

1) Scope and Purpose
2) Roles and Responsibilities
3) Guideline Statements
4) Operational Considerations

32
Q

Separation of Duties

A

Requiring multiple people to take part in completing a process so as to minimize errors and malpractice.

33
Q

Privacy Policies

A

Outlines how data collected is secured.

34
Q

Acceptable Use Policies (AUP)

A

How the employees can use company systems and resources.

35
Q

Pod Slurping

A

Plugging directly into a machine (like with a USB) to bypass security and download or upload stuff

36
Q

Mandatory Vacation Policy

A

Requires all users to take time away from work

37
Q

Job Rotation Policy

A

Defines intervals at which employees must rotate through positions so that a company does not become too dependent on one person.

38
Q

False Positives

A

Events that aren’t actually incidents

39
Q

False Negatives

A

When you are not alerted to a situation to which you should be alerted

40
Q

Clustering

A

Using multiple servers to load balance and create redundancy.

41
Q

Which power redundancy device should be used for short-term outages? For long term?

A

Uninterruptible Power Supply (UPS)

Backup Generator

42
Q

Redundant Array of Independent Disks

A

Uses multiple disks to provide fault tolerance

43
Q

Tabletop Exercise

A

Involves individuals sitting around a table with a facilitator discussing situations that could arise and how best to respond to them.

44
Q

3 Types of Controls

A

1) Technical
2) Management
3) Operational

45
Q

RAID Level 0

A
  • Disk Striping
  • Uses multiple drives and maps them together as a single physical drive.
  • One fails, unusable
46
Q

RAID Level 1

A
  • Disk Mirroring

- Two disks with exact copies of all the info

47
Q

RAID Level 3

A
  • Disk Striping with a Parity Disk

- Parity Info is kept on a separate disk for recovery

48
Q

Parity Information

A

A value based on the arithmetic value of the data binary.

49
Q

RAID Level 5

A
  • Disk Striping with Parity

- Parity info spread across all disks instead of a single disk

50
Q

Change Management

A

The structured approach that is followed to secure a company’s assets