Information Risk Management Flashcards

1
Q

What is Risk ?

A

Risk = Threat * Vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk Management Lifecycle is

A

iterative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Lifecycle phases?

A

IT Risk Identification
IT Risk Assessment
Risk Response And Mitigation
Risk and Control Monitoring and Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the steps to do Risk Managing as in program management

A

Identify our Risk Management team
What is in and what is out of scope?
Which methods are we using?
Which tools are we using?
What are the acceptable risk levels, which type of risk appetite do we have in our enterprise?
Identify our assets: Tangible and Intangible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the steps of Risk Assessment?

A

Quantitative and Qualitative Risk Analysis
Uncertainty analysis
Everything is done on a cost-benefit analysis
Risk Mitigation/Risk Transference/ Risk Acceptance/ Risk Avoidance
Risk Rejection is NEVER acceptable
We assess the current countermeasures: Are they god enough? Do we need to improve on them? Do we need to implement entirely new countermeasures?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe Qualitative Risk Analysis

A

How likely is it to happen and how bad is it if it happens?
This is a vague guess or a feeling, and relatively quick to do. Most often done to know where to focus the Quantitative Risk Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe Quantitative Risk Analysis

A

What will actually cost in $? This is fact based analysis, Total $ value of asset, math is involved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Threat?

A

A potentially harmful incident (Tsunami, earthquake, tornado…)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is vulnerability?

A

A weakness that can allow the threat to do harm. having a data center in the tsunami flood area, not earthquake resistant, not applying patches and antivirus,..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you describe the Impact?

A

Can at times be added to give a more full picture. Risk= ThreatVulnerabilityImpact (How bad is it?)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Total risk defined?

A

TR= Threat * Vulnerability * Asset Value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Residual Risk?

A

Total Risk - Countermeasures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tool is usually used to make a qualitative risk analysis?

A

A Risk Analysis Matrix usually 6 by 6 where the columns can starts from (left to right) insignificant, Minor, Moderate, Major, and Catastrophic; and the Rows start (top left to bottom left) with Almost Certain, Likely, Possible, unlikely, and Rare

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How would you rate the loss of a laptop?

A

How likely is one get stolen or left somewhere? (Possible or Likely) and the risk could be L= Low; M = Medium; H = High; E= Extreme)
How bad if it happens? it would depend if the laptop is encrypted or has PII/PHI content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What other tool is also used for qualitative analysis?

A

Risk Registers: a spreadsheet with the following columns: Category, Name, Risk #, Probability, Impact, Mitigation, Contingency, Risk Score after Mitigation, Action By, and Action When

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Describe Quantitative Analysis

A

Is when we want exactly enough security for our needs: This is where we put a number on that. We find the asset’s value : How much of it is compromised, how much one incident will cost, how often the incident occurs and how much that is per year.

17
Q

What is AV?

A

Asset value - How much is the asset worth?

18
Q

What is EF?

A

Exposure Factor - Percentage of Asset Value Lost?

19
Q

What is SLE - (AV*EF) ?

A

What does it cost if it happens once?

20
Q

Annual Rate of Occurrence (ARO)

A

How often will this happen each year?