Chapter 2 Personnel Security and Risk Management Concepts Flashcards
________ is the collection of practices related to supporting, defining, and
directing the security efforts of an organization.
Security governance
Any potential occurrence that may cause an undesirable or unwanted outcome
for an organization or for a specific asset
Threats Vulnerability Exposure Risk Attack Breach
Threats
The weakness in an asset or the absence or the weakness of a safeguard or
countermeasure
Threats Vulnerability Exposure Risk Attack Breach
Vulnerability
being susceptible to asset loss
Threats Vulnerability Exposure Risk Attack Breach
Exposure
possibility or likelihood that a threat will exploit a vulnerability to cause
harm to an asset
Threats Vulnerability Exposure Risk Attack Breach
Risk
any intentional attempt to exploit a vulnerability of an organization’s security
infrastructure to cause damage, loss, or disclosure of assets.
Threats Vulnerability Exposure Risk Attack Breach
Attack
the occurrence of a security mechanism being bypassed or thwarted by a threat agent.
Threats Vulnerability Exposure Risk Attack Breach penetration
Breach
the percentage of loss that an organization would experience if a specific asset were violated by a realized risk.
Exposure Factor
Single Loss Expectancy
Annualized Rate of Occurrence
Annualized Loss Expectancy
Exposure Factor
the cost associated with a single realized risk against a specifi c asset. It indicates
the exact amount of loss an organization would experience if an asset were harmed by a
specific threat occurring.
Exposure Factor
Single Loss Expectancy
Annualized Rate of Occurrence
Annualized Loss Expectancy
Single Loss Expectancy
the expected
frequency with which a specifi c threat or risk will occur (that is, become realized) within
a single year.
Exposure Factor
Single Loss Expectancy
Annualized Rate of Occurrence
Annualized Loss Expectancy
Annualized Rate of Occurrence
the possible yearly
cost of all instances of a specific realized threat against a specific asset.
Exposure Factor
Single Loss Expectancy
Annualized Rate of Occurrence
Annualized Loss Expectancy
Annualized Loss Expectancy
Security controls, countermeasures, and safeguards can be implemented ______, _______ and __________ .
administratively,
logically/technically, or physically
AV * EF =
ARO
SLE
ALE
SLE
SLE * ARO =
ARO
SLE
ALE
ALE
threats * vulnerabilities * asset value =
total risk