Domain 1 Flashcards
What does IAAAA stand for?
Identification Authentication Authorization Accountability Auditing
What does DAD stand for ?
Disclosure
Alteration
Destruction
What are four protection mechanisms?
Layering
Abstractions
Data Hiding
Encryption
What are the rules of risk management?
- No risk can be completely avoided.
- Risks can be minimized and controlled to avoid impact of damages.
- Risk management is the process of identifying, examining, measuring, mitigating, or transferring risk.
What are the 5 types of risk management frameworks?
Preventative Déterrent Détective Corrective Recovery
What are examples of preventative risk management ?
Security policies Security cameras Callback Security awareness training Job rotation Encryption Data classification Smart cards
What are examples of deterrent risk management ?
Security personnel Guards Security cameras Separation of duties Intrusion alarms Awareness training Firewalls Encryption
What are examples of detective risk management ?
Logs Security cameras Intrusion detection systems Honey pots Audit trails Mandatory vacations
What are examples of corrective risk management ?
Alarms
Antivirus solutions
Intrusions detection systems
Business continuity plans
What are examples of recovery risk management ?
Backups Server clustering Fault tolerant drive systems Database shadowing Antivirus software
What is the risk management life cycle?
Assessment
Analysis
Mitigation
Response
What types of responsibilities fall under risk management assessment?
System characterization Threat identification Vulnerability identification Control analysis Likelihood détermination Impact analysis Risk determination Control recommendation Results documentation
What types of responsibilities fall under risk management analysis?
Qualitative Quantitative AV - Asset value EF- Exposure factor ARO - Annual rate of occurrence Single loss expectancy = AV * EF Annual loss expectancy = SLE * ARO Risk value = probability * impact
What types of responsibilities fall under risk management mitigation/recovery?
Reduce/Avoid
Transfer
Accept/Reject
What are the six steps of the risk management framework ?
Categorize Sélect Implement Assess Authorize Monitor