Cybersecurity Operational Components Flashcards
1
Q
What are some of the technology controls for Risk logs?
A
- Risk management software
- General tracking software
2
Q
What are some of the process controls for Risk logs?
A
- Regular log review
- Update on-going risks
- Clearly identified responsibilities
3
Q
What are some technology controls for Risk responses?
A
- Risk management software
- Risk register
4
Q
What are some process controls for Risk responses?
A
- Enterprise Risk Management (ERM)
- Positive risk culture
- Risk treatment plan
5
Q
What’s the definition of Residual risk?
A
Risk that remains after identifying and responding to a risk.
6
Q
What are some technology controls for Metrics and reporting?
A
- Data collection points
- Monitoring systems
- Data storage and access controls
- Automated reporting tools
7
Q
What are some process controls for Metrics and reporting?
A
- Security audits
- Risk assessments
- Risk registers
- Cost-risk analysis