Chapter 2: Risk Management Flashcards
Risk management
process of identifying and assessing risk, reducing it to an acceptable level, and ensuring it remains at that level
ISRM policy
information systems risk management policy; provides foundation/direction for the org’s security risk management processes and procedures and should address all issues of information security
Threat
a potential cause of an unwanted incident, which may result in harm to a system or org
Risk assessment methodology
NIST SP 800-30
FRAP
Facilitated Risk Analysis Process
OCTAVE
Operationally Critical Threat, Asset, and Vulnerability Evaluation
FMEA
Failure Modes and Effect Analysis
FMEA
Failure Modes and Effect Analysis; method for determining functions, identifying functional failures, and assessing the causes of failure and their effects through a structured process
Fault tree analysis
a useful approach to detect failures which can take place within complex environments and systems
Quantitative risk analysis
attempts to assign monetary values to components within the analysis
Qualitative risk analysis
Uses judgment and intuition instead of numbers because qualitative items cannot be quantified with precision; involves people with requisite experience and education evaluating threat scenarios and rating the probability, potential loss, and severity of each threat based on their personal experience
SLE
Single loss expectancy
ARO
annual rate of occurrence; frequency per year
ALE
annualized loss expectancy
Annualized loss expectancy calculation
SLE x ARO = ALE