J. Risks Objectives Flashcards
What a strategy describes
How goal and objectives are to be met.
What inputs to consider before developing objectives
Risk assessments and Threat assessments.
Why a risk assessment
To reveal risks present in the organization.
Result of risk assesement
Provides a strategist with valuable information on the types of resources required to bring risks down to an acceptable levels.
Why performing a threat assessment
To better understand relevant threats.
Result of threat assessment
Gives the strategist information about the types of threats most likely to have an impact on the organization, regardless of the effectiveness of controls.
Why performing a threat assessment provides an additional perspective on risk
Because a threat assessment focuses on external threats and threat scenarios, regardless of the presence or effectiveness of preventive or detective controls.
Security policy
Is thought of as an organization’s internal laws and regulations with regard to the protection of important assets.
Security Standards
Describes in detail the methods, techniques, technologies, specifications, brands, and configurations to be used throughout the organization.
Guidlines
Provides more details on how to adhere to policies.
Organization’s achitechture
Documentation of systems, networks, data flows and other aspects of its environments.
Technical debt
Poor design and
outdated and unsupported components
When is technical debt accumulated
When organizations lack personnel capable of creating good architectural designs and also when an organization fails to upgrade end-of-life components.
Last Page
81 - Control