Chapter 1 - Measuring & Weighing Risk Flashcards
What is a vulnerability?
1-3
a weakness that could be exploited by a threat
Give the formula for “impact” and explain the terms in the formula.
1-5
SLE x ARO = ALE
(AV x EF) x ARO = ALE
SLE - single loss expectancy, determined by multiplying the asset value by the exposure factor
ARO - annualized rate of occurrence
ALE - annual loss expectancy
EF - exposure factor)
True or False
SLE, ALE, and ARO are all quantitative.
1-7
True. All number based.
What is a threat vector?
1-8
a tool or path an attacker uses to pose a threat
What is MTBF?
1-8
Mean Time Between Failures. Basically it tells you the lifespan of the device.
What is MTTF?
1-8
Mean Time To Failure. Tells you average time to failure for a nonrepairable system.
What is MTTR?
1-8
Mean Time To Restore. Tells you how long it will take to repair a system.
What is RTO?
1-9
Recovery Time Objective. This tells you how much time you’re allotted to use for restoring the system.
What is RPO?
1-9
Recovery Point Objective. This is the point in time at which the system was last operational and therefore what you need to restore it to.
Contrast Risk Avoidance, Transference, Mitigation, Deterrence, and Acceptance.
1-9,10
Avoidance-stop doing the stuff that causes the risk.
Transference-share the risk
Mitigation-lower the risk
Deterrence-tell the risk creator “if you do this to me, I’ll do this to you.”
Acceptance-live with the risk and don’t do anything about it because its the cheaper alternative.
Explain PaaS, Saas, IaaS.
Tell me 2 risks associated with virtualization.
1-17,18,19
platform as a service
software as a service
infrastructure as a service
breaking out of the virtual machine
network and security controls can intermingle
What is Hypervisor?
1-19
the software that allows virtual machines to exist
What is the Scope Statement?
What is the Accountability Statement?
1-19
outlines what the policy intends to accomplish
who is responsible for ensuring that a problem gets dealt with
5 Key Aspects of Standards Documents
1-21,22
Scope and Purpose Roles and Responsibilities Reference Documents Performance Criteria Maintenance and Administrative Requirements
How are guidelines different from standards?
1-22
Guidelines tell you HOW to enforce standards.