Chpt 2 Flashcards

1
Q

What is the equation for ALE?

A
ALE = Annual Loss Expectancy
ALE= SLE x ARO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the equation for safeguard evaluation?

A

Safeguard Evaluation = ALE before safeguard - ALE after safeguard - annual cost of safeguard.

(ALE1 - ALE2) - ACS = safeguard evaluation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 6 administrative control types?

A
  1. Preventative
  2. Detective
  3. Corrective
  4. Deterrent
  5. Recovery
  6. Directive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the difference between training and education?

A

Training is basic for every employee to comply with standards in security policy.

Education is more detailed and above and beyond what they need to know. Usually for advancement or promotion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the six steps of management framework?

A

CSIAAM

  1. Categorize
  2. Select
  3. Implement
  4. Assess
  5. Authorize
  6. Monitor
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you calculate SLE?

A

SLE = AV x EF

SLE = assets value * exposure factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define overall risk management

A

The process of identifying factors that could damage or disclose data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is it called when there is an absence or weakness of a safeguard or countermeasure?

A

A vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is it called when there are accidental or intentional exploitation’s of vulnerabilities?

A

Threat events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is it called when there is a logical and practical investigation of buisness processes and organizational policies?

A

Documentation review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the primary focus of the exit interview?

A

To go over the NDA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the first step in hiring new employees?

A

Creating a job description.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When working on a quantitative risk analysis, adjusting a countermeasure changes what factor?

A

ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly