Dealing with Risk Flashcards

1
Q

Control types

A

Technical security controls

Management security controls

Operational security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

False Postitives

A

report that isn’t true - a false alarm or mistaken identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

False Negatives

A

A report missed identifying something - no notification

Malicious traffic got through your defenses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security policies

A

A set of policies that covers many areas of security

Human resource policies
Business policies
Certificate policies
Incident-response policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Calculation

A

Annualized Rate of Occurrence (ARO)

SLE (Single Loss Expectancy)

ALE (Annual Loss Expectancy) = ARO x SLE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Quantitative Risk Assessment

A

Assign a dollar value to risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Qualitative Risk Assessment

A

Identify significant risk factors

Ask opinions about the significance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Threat Assessment

A

Where are we vulnerable to threats?

OS, applications, 3rd-party connections, Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Vulnerability Assessment

A

Actively scan a network in search of vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vulnerabilities

A

A flaw or weakness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Threat Vectors

A

The path that the threat takes to the target

Target: Your computer, mobile device, gaming system

Email: Embedded links, attached files
Web browser: Fake site, session hijack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Threat Probability

A

Identify actual and potential threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Deflecting Risk

A

Risk-avoidance

Stop participating in high-risk activity

Risk transference
Buy some insurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Mean time to restore (MTTR)

A

Mean time to repair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Mean time to failure (MTTF)

A

The expected lifetime of a product or system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Mean time between failures (MTBF)

A

Predict the time between failures

17
Q

Recovery time objectives (RTO)

A

Get up and running quickly

Get back to a particular service level

18
Q

Recovery point objectives (RPO)

A

How much data loss is acceptable?

Bring the system back online; how far back does data go?