Chapter 8 Sec + Flashcards

1
Q

AV

A

Asset Value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

EF

A

Exposure Factor
Is the portion of an Asset that we expect would be DAMAGED if a risk materializes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SLE

A

Single loss expectancy
Is the combination of AF×EF=SLE
Asset worth 10,000AV x
Exposure Factor 40% .4
10,000x.4=$4000 || SLE 4000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ARO

A

Annualized Rate of Occurrence
Indicates how many times the loss will occur in a year
If aro is less then 1 it’s represented in decimal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ALE

A

Annual Loss Expectancy
SLE x ARO =ALE
5000 x 6 = 30000
30000 will be the annual cost of replacing the gear

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CVE

A

Common Vulnerabilities and Exposures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CVSS

A

Common Vulnerability Scoring System
Assesses vulnerabilities and assigns severity score in a range from 0 to 10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

RD

A

Responsible Disclosure
Programs for vulnerability enabled individuals and orgs to report security vulnerabilities or weakness they’ve found

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CIS

A

center for Internet security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISMS

A

Information Security Management System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PIMS

A

Privacy Information Management system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RMF

A

Risk Management Framework
7 steps
Prepare
Categorize
Select
Implement
Access
Authorize
Monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CSF

A

Cyber security Framework
Includes 3 components

Core- a set of activities that an org can select to achieve desired outcome

Tiers- helps an org identify how it views risks

Profile- provides a list of outcomes based on its needs and risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SCAP

A

Security Content Automation Protocol

Is designed to facilitate communicate between Vulnerability Scanners and other Security Management Tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

KRI

A

Key Risk Indicators

Are Metrics used to measure and Monitor the Level of Risk associated with a particular Activity, Process, or system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly