Chapter 1: Measuring and Weighing Risk Flashcards
Residual Risk
A risk that must remain for some reason
BIA
- Business Impact Analysis
- Outlines how to respond to various situations
Steps to Develop an Overview of Risk
1) Interview the department heads
2) Evaluate the network infrastructure
3) Perform a physical assessment
Annual Loss Expectancy (ALE)
A monetary measure of how much loss you could expect in a year.
Single Loss Expectancy (SLE)
How much you expect to lose at any one time.
Two components of SLE
1) Asset Value (AV)
2) Exposure Factor (EF)
Annualized Rate of Occurrence (ARO)
Likelihood of an event occurring within a year
Risk Assessment Formula
SLE x ARO = ALE
Qualitative Risk Assessment
Opinion-based and subjective
Quantitative Risk Assessment
Cost-based (money) and objective
Likelihood
A score from 1-10 assessing the likelihood of an event
Threat Vector
The way in which an attacker poses a threat.
Mean Time Between Failures (MTBF)
Lifetime of a component before it must be replaced or repaired
Mean Time To Failure (MTTF)
The average time to failure for a nonrepairable system.
Mean Time To Restore (MTTR)
How long it takes to repair something once it fails.
Recovery Time Objective (RTO)
Max time that a process is allowed to be down before negative effects begin happening.
Recovery Point Objective (RPO)
The point the system needs to be restored to
Risk Avoidance
Identifying a risk and deciding to not engage in the actions associated with that risk
Risk Transference
Share some of the burden of risk with someone else, such as an insurance company.
Risk Mitigation
Taking steps to reduce risk