IS Risk Assesments Flashcards

1
Q

What are the three possible IAP threat categories?

A

1) Intentional
2) Natural
3) Inadvertent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 8 steps of an IAP Risk Assessment Process?

A

1) Identify information assets
2) Valuate information assets
3) Assess threats to information assets. Likely adversaries4) Assess likelihood of threat occurrence
5) Identify existing and projected vulnerabilities
6) Asses the impact of a loss event or disclosure on the organization
9) Identify existing and planned security controls or other options for addressing risk.
8) Assess and prioritize risk based on the likelihood and organizational impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the difference between Residual Risk and Residual Threat Risk? What is the qualitative fundamental equation of ISS?

A

Residual Threat Risk is the leftover risk for each threat. Residual Risk is the total leftover risk for all risks.

Residual Risk = (Threats*Vulnerabilities)/Countermeasures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an information system threat?

A

Any circumstance, capability, action, or event with the potential to adversely impact an information system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Information Systems Vulnerability

A

A flaw or weakness in an information systems design that could be exploited to violate a system’s security policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Information System Risk equation?

A

(level of threat) * (level of vulnerability)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When should an ISS risk assessment be carried out?

A

A regular and systematic basis to address changes that may occur in the business environment as well as security requirements and the nature of in the information assets, threats, vulnerabilities and impacts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly