Governance Flashcards

1
Q

Risk Profile

A

Is based on the aggregate risk to the enterprise, including historical risk, critical risk, and emerging risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Owner of Risk Treatment

A

Senior management owns the risk treatment decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk Treament Plan Owner

A

Owns the Risk Treatment Plan and the monitoring of the plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

First Line Of Defense

A

Operational Managers (business owners), Are responsible for managing risk. They are responsible for implementing corrective action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Relevance Risk

A

Composite form of risk requiring both Integrity and Availability risk. Could create access risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

3 Lines Of Defense

A

1st Line is Operations Functions
2nd Line is compliance, ethics, risk management.
3rd Line is internal auditing, independent verification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Most Effective at Managing and Executing Risk Management

A

Mid Level Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Primary Goal of Risk Management Process

A

Is to protect the enterprise and its ability to perform its mission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Best supports effort to successfully deliver to business requirements

A

Internal control system or FRAMEWORK.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Most concern for a security practitioner is

A

Not reporting successful attack. This is called abetting and worse than not periodically checking permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly