Lesson 18 - Summarizing Report Components Flashcards

1
Q

What is the term of people not directly involved with the client but who may still be involved. Providers, investors, regulators and similar entities

A

Third Party Stakeholders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the process of assigning values to the identified risk referred to:

Also what is the scoring system that is published by NIST called

A

Risk Rating

Common Vulnerability Scoring System (CVSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the process of adjusting the final ratings of vulnerabilities to the client needs

A

Risk Prioritization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the post-activity that identifies organizational risk and determines their effect on ongoing, mission critical operations

A

Business Impact Analysis (BIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe the difference between a metric and measures

A

Metrics are quantifiable measurements of results or processes and can be expressed on a scale say from 1 to 10.

Measures are specific datapoints that contribute to a metrics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Outline a typical and recommended format for the delivery of the PenTest

A

Executive summary
Scope details
Methodology
Attack narrative
Findings
Risk rating
Risk prioritization
Metrics and measures
Remediation
Conclusion
Appendix or supporting evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly