Lesson 19 Risk Management Flashcards

1
Q

Phases of Risk Management

A

Identify:
1. Mission essential functions

  1. Vulnerabilities and Weakness for each function or workflow
  2. Threats for each function or workflow which attackers may exploit
  3. Analyze business impacts of vulnerability being activated
  4. Risk response, countermeasures, and cost for mitigation of the risk
    - Safety is number one
    - cost/money is second
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Likelihood of occurrence

A

The probability of the threat being realized

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Impact of realized security incident

A

Impact is the severity of the risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

MTBF - Mean Time Between Failures

A

Mean Time Between Failures (MTBF)

How often failures are expected to happen

total time / number of failures

Calculation:
( 10 devices)(50 hours)/(2 failures) = 250 hours/failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

MTTR - Mean Time To Repair/Replace/Recover

A

Mean Time to Repair (MTTR)
the average amount of time to repair/replace/recover the product or to correct a fault

important for determining RTO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SPoF - Single Point of Failure

A

Single Point of Failure (SPoF)
a component or system that would cause a complete interruption of a service if it failed

Mitigate by provisioning redundant components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

RTO - recovery Time Objective

A

Recovery Time to Objective (RTO)

Time taken to get system up again
or
The planned max amount of recovery and restoration time

RTO+WRT must not exceed MTD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

WRT - work recovery time

A

Work Recovery Time
Following system recovery, how long to get system working again

RTO+WRT must not exceed MTD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RPO - Recovery Point Objective

A

Recovery Point Objective (RPO)

maximum time an organization can tolerate lost data being unrecoverable
aka which backups to use during recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

MEF - Mission Essential Function

A

Mission Essential Function

a critical function of the mission which cannot be deferred for more than a few hours, if at all

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

MTD - Maximum Tolerable Downtime

A

Maximum Tolerable Downtime (MTD)

longest period of time a business can be inoperable without causing irrecoverable business failure

RTO+WRT must not exceed MTD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk Register

A

a document showing the results of a risk assessment in an easy to read format

Should be shared amongst all shareholders to help them understand the risk associated with the workflows they manage

Identify potential risks and their impact/likelihood
Display the company’s mitigation plan for each risk
Assign responsibility for the execution of those plans
Track the status of each plan (complete, in-progress, not started, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Quantitative Risk Analysis
Annualized Loss Expectancy calculations
know for test

A

SLE - Single Loss Expectancy
ARO - Annualized Rate of Occurrence
ALE - Annualized Loss Expectancy

SLE * ARO = ALE

know for test: ‘the incident costs X’ is the SLE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SLE

A

Single Loss Expectancy

the amount which would be lost in a single occurrence of the risk factor

determine by Exposure Factor EF and Asset Value

SLE = EF * AV

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ARO

A

Annualized Rate of Occurrence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ALE

know how to calculate this

A

Annualized Loss Expectancy

The amount which would be lost over the course of a year

ALE = SLE * ARO

17
Q

DRP - Disaster Recovery Plan

A

Disaster Recover Plan

a plan of how to recover the system or site to a working state following a disaster level event

Identify
- scenarios
- tasks
- resources
- responsibilities
Train staff
18
Q

FRP - functional recovery plans

A

Functional Recovery Plans

Due to rare occurrence of disasters, functional recovery plans determine how effective the recovery plan is
Perform:
- Training though walkthroughs workshops and seminars
- Tabletop exercises
- Functional exercises
- Full-scale exercises

19
Q

Risk types

A

External
Internal
Multiparty - arrises from supplier relationships
Intellectual Property Theft
SW Compliance/Licensing
Legacy Systems - not as secure due to lack of patching

20
Q

Risk Mitigation or remediation

A
process of reducing exposure to or the effects of risk factors
Risk Deterrence
Risk Reduction
Risk Avoidance
Risk Transference
21
Q

Risk Deterrence vs Risk Reduction

A

Risk deterrence is deploying a countermeasure to reduce exposure to a threat or vulnerability

Risk reduction are controls which make a risk incident less likely or less costly or both

22
Q

Risk Avoidance

A

means to stop doing the activity which is risk bearing

23
Q

Risk Transference

A

Assigning risk to a third party

24
Q

Inherent Risk

A

Risk before being mitigated

25
Q

Residual Risk

A

likelihood and impact after mitigation, transference, or acceptance measures have been applied

26
Q

Control Risk

A

risk that arises when a control does not provide the level of mitigation that was expected

could be a security control which was never effective in mitigating inherent risk