Domain 3 Flashcards
IRM
Information Risk Management. Risks and threats identified. Vulnerabilities reduced and controls implemented.
Exposure factor
Estimated percentage of loss should a threat exploit the vulnerability in an asset.
SLE Calculation
SLE= Asset Value x EF (%)
Threat action/Threat agent
Actual threat
Threat vector
Path a threat takes to cause an action
ISO 27005
Information Risk Management framework
NIST 800-37 rev 1
Risk management framework for federal info systems
ALE calc
ALE=SLE x ARO
ARO expressed as…
Percentage betwen 0.0 and 1.0
Analysis vs. Assessment
Perform an analysis. Results of analysis enable you to make an assessment
NIST 800-30
Guide for conducting risk assessments
Risk treatment plan
Determine who is responsible for controls with time frame and budget
MIB
SNMP Management information Base. Resides on the device and contains info about it. Responds to SNMP agent.
SNMP Agent
SNMP responder on the device
Passive monitoring
Capture traffic on a device using span/mirror port