Chapter 8 Sec + Flashcards
AV
Asset Value
EF
Exposure Factor
Is the portion of an Asset that we expect would be DAMAGED if a risk materializes
SLE
Single loss expectancy
Is the combination of AF×EF=SLE
Asset worth 10,000AV x
Exposure Factor 40% .4
10,000x.4=$4000 || SLE 4000
ARO
Annualized Rate of Occurrence
Indicates how many times the loss will occur in a year
If aro is less then 1 it’s represented in decimal
ALE
Annual Loss Expectancy
SLE x ARO =ALE
5000 x 6 = 30000
30000 will be the annual cost of replacing the gear
CVE
Common Vulnerabilities and Exposures
CVSS
Common Vulnerability Scoring System
Assesses vulnerabilities and assigns severity score in a range from 0 to 10
RD
Responsible Disclosure
Programs for vulnerability enabled individuals and orgs to report security vulnerabilities or weakness they’ve found
CIS
center for Internet security
ISMS
Information Security Management System
PIMS
Privacy Information Management system.
RMF
Risk Management Framework
7 steps
Prepare
Categorize
Select
Implement
Access
Authorize
Monitor
CSF
Cyber security Framework
Includes 3 components
Core- a set of activities that an org can select to achieve desired outcome
Tiers- helps an org identify how it views risks
Profile- provides a list of outcomes based on its needs and risk management
SCAP
Security Content Automation Protocol
Is designed to facilitate communicate between Vulnerability Scanners and other Security Management Tools
KRI
Key Risk Indicators
Are Metrics used to measure and Monitor the Level of Risk associated with a particular Activity, Process, or system.