Chapter 5 Flashcards

1
Q

What is risk management?

A

process of identifying and controlling risks facing an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is risk identification?

A

process of examining an organization’s current information technology security situation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is risk control?

A

applying controls to reduce risks to an organization’s data and information systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is risk appetite?

A

defines quantity and nature of risk that organizations are willing to accept as trade-offs between perfect security and unlimited accessibility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is residual risk?

A

risk that has not been completely removed, shifted, or planned for.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

People, Procedures and Data Asset Identification

A

Human resources, documentation and data information.

People: position name/number/ID, supervisor, security clearance level, special skills.

Procedures: description, intended purpose.

Data: classification, owner, creator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is risk assessment?

A

Risk assessment evaluates the relative risk for each vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly