Governance Flashcards
Risk Profile
Is based on the aggregate risk to the enterprise, including historical risk, critical risk, and emerging risk.
Owner of Risk Treatment
Senior management owns the risk treatment decisions
Risk Treament Plan Owner
Owns the Risk Treatment Plan and the monitoring of the plan
First Line Of Defense
Operational Managers (business owners), Are responsible for managing risk. They are responsible for implementing corrective action.
Relevance Risk
Composite form of risk requiring both Integrity and Availability risk. Could create access risk.
3 Lines Of Defense
1st Line is Operations Functions
2nd Line is compliance, ethics, risk management.
3rd Line is internal auditing, independent verification.
Most Effective at Managing and Executing Risk Management
Mid Level Management
Primary Goal of Risk Management Process
Is to protect the enterprise and its ability to perform its mission.
Best supports effort to successfully deliver to business requirements
Internal control system or FRAMEWORK.
Most concern for a security practitioner is
Not reporting successful attack. This is called abetting and worse than not periodically checking permissions.