Chapter 8: Using Risk Management Tools Flashcards
A ____ is the likelihood that a threat will exploit a vulnerability.
risk
A ____ is a potential danger that can compromise confidentiality, integrity, or availability of data or a system.
threat
A ____ is a weakness.
vulnerability
____ refers to the magnitude of harm that can be caused if a threat exercises a vulnerability.
Impact
___ ____ help an organization identify and categorize threats.
Threat assessments
An____ threat assessment evaluates the likelihood of an environmental threat, such as a natural disaster, occurring.
environmental
____ threat assessments evaluate threats from humans.
Manmade
____ threat assessments evaluate threats from within an organization.
Internal
____ threat assessment evaluates threats from outside an organization.
External
A _____ is a flaw or weakness in software or hardware, or a weakness in a process that a threat could exploit, resulting in a security breach.
vulnerability
Risk management attempts to reduce risk to a level that an organization can accept, and the remaining risk is known as ____ risk.
residual
You can avoid a risk by not providing a service or participating in a risky activity. Purchasing insurance, such as fire insurance, transfers the risk to another entity. Security controls mitigate, or reduce, risks. When the cost of a control outweighs a risk, it is common to ____ ___ ____.
accept the risk
A ___ _____ quantifies or qualifies risks based on different values or judgments. It starts by identifying asset values and prioritizing high-value items.
risk assessment
____ risk assessments use numbers, such as costs and asset values.
Quantitative
The ___ ___ ___ is the cost of any single loss.
single loss expectancy (SLE)
The ____ __ ___ ____ indicates how many times the loss will occur annually.
annual rate of occurrence (ARO)
You can calculate the annual loss expectancy (ALE) as ___ x ____
SLE × ARO.
_____risk assessments use judgments to prioritize risks based on likelihood of occurrence and impact. These judgments provide a subjective ranking.
Qualitative