Chapter 5 Flashcards
What is risk management?
process of identifying and controlling risks facing an organization
What is risk identification?
process of examining an organization’s current information technology security situation.
What is risk control?
applying controls to reduce risks to an organization’s data and information systems.
What is risk appetite?
defines quantity and nature of risk that organizations are willing to accept as trade-offs between perfect security and unlimited accessibility
What is residual risk?
risk that has not been completely removed, shifted, or planned for.
People, Procedures and Data Asset Identification
Human resources, documentation and data information.
People: position name/number/ID, supervisor, security clearance level, special skills.
Procedures: description, intended purpose.
Data: classification, owner, creator.
What is risk assessment?
Risk assessment evaluates the relative risk for each vulnerability.