Chapter 3: IT Risk Response and Mitigation Flashcards

1
Q

The risk response decision is based on

A

the information provided in the earlier steps of risk identification and assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The risk response must ensure that

A

business operations are protected but not unduly impaired or impacted by controls that are put in place to address risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the four commonly accepted risk response options?

A

risk acceptance
risk mitigation
risk avoidance
risk transfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In risk acceptance, who is responsible for the risk in case it occurs?

A

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is risk acceptance?

A

It is the amount of risk that senior management has determined is within acceptable or permissible bounds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is risk ignorance?

A

It is the failure to identify or acknowledge risk or it is a decision to blindly accept risk without knowing what the risk level really is

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When is risk tolerance used?

A

in an exceptional circumstance where the level of risk may exceed the risk acceptance boundary set by senior management but the decision is made to accept the risk anyway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is self insurance?

A

Deciding to absorb the potential costs of an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is risk mitigation?

A

Acton is taken to reduce the frequency and/or impact of risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is risk avoidance?

A

Exiting the activities or conditions that give rise to the risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When does risk avoidance apply?

A

there is no other cost-effective response that can succeed in reducing the frequency and impact below the defined thresholds for risk appetite
the risk cannot be shared or transferred
the exposure level is deemed unacceptable by management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is risk transfer?

A

the decision to reduce loss through sharing the risk of loss with another organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What factors should be considered in selecting a risk response?

A

priority of the risk
recommended control from the risk assessment report
other response alternatives
cost of the various response options
requirements for compliance with regulations or legislation
alignment of the response option with the strategy of the organization
possibility of integrating the response with other organizational initiatives
compatibility with other controls in place
time, resources, and budget available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

This analysis is used to justify the expense associated with the implementation of controls

A

cost benefit analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the factors that must be included in the calculating the total cost of the control:

A

Cost of acquisition
Cost of maintenance
Cost to remove / replace the control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly