Chpt 2 Flashcards
What is the equation for ALE?
ALE = Annual Loss Expectancy ALE= SLE x ARO
What is the equation for safeguard evaluation?
Safeguard Evaluation = ALE before safeguard - ALE after safeguard - annual cost of safeguard.
(ALE1 - ALE2) - ACS = safeguard evaluation.
What are the 6 administrative control types?
- Preventative
- Detective
- Corrective
- Deterrent
- Recovery
- Directive
What is the difference between training and education?
Training is basic for every employee to comply with standards in security policy.
Education is more detailed and above and beyond what they need to know. Usually for advancement or promotion.
What are the six steps of management framework?
CSIAAM
- Categorize
- Select
- Implement
- Assess
- Authorize
- Monitor
How do you calculate SLE?
SLE = AV x EF
SLE = assets value * exposure factor
Define overall risk management
The process of identifying factors that could damage or disclose data.
What is it called when there is an absence or weakness of a safeguard or countermeasure?
A vulnerability
What is it called when there are accidental or intentional exploitation’s of vulnerabilities?
Threat events
What is it called when there is a logical and practical investigation of buisness processes and organizational policies?
Documentation review
What is the primary focus of the exit interview?
To go over the NDA.
What is the first step in hiring new employees?
Creating a job description.
When working on a quantitative risk analysis, adjusting a countermeasure changes what factor?
ARO