Lecture 14 Flashcards
What is a risk in the context of information security?
Risk is the potential for loss, expressed as the probability that a threat will exploit a vulnerability with a harmful result.
What is the primary goal of risk management?
To reduce risk to an acceptable level.
What are the key components of risk analysis?
- Identifying threats
- Evaluating likelihood
- Assessing damage cost
- Analyzing countermeasure costs
Define ‘asset’ in risk management.
A system resource that has value and requires protection.
What is a vulnerability?
A weakness in an asset’s design, implementation, or management that could be exploited.
How do you calculate risk in quantitative risk analysis?
Risk = Probability of Threat × Impact Cost
What is qualitative risk analysis?
A risk analysis approach based on expert judgment rather than numerical values.
What are the four risk treatment strategies?
- Risk acceptance
- Risk avoidance
- Risk transfer
- Risk reduction
What is the ‘Defense in Depth’ strategy?
A security strategy using multiple layers of defense mechanisms.
Name the three main security goals.
- Confidentiality
- Integrity
- Availability
What are examples of security controls?
- Encryption
- Access controls
- Firewalls
- Intrusion detection systems
What is non-repudiation in security?
Assurance that an entity cannot deny having performed an action.