Lot 5 Flashcards

1
Q

A subset of risk indicators that are highly relevant and

possess a high probability of predicting or indicating important risk

A

Key risk indicator (KRI) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The principle of allowing users or applications the least amount of
permissions necessary to perform their intended function

A

Least privilege -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A means of restricting access to data based on
varying degrees of security requirements for information contained in the objects and the
corresponding security clearance of users or programs acting on their behalf

A

Mandatory access control (MAC) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Maximum time the organization can support

processing in alternate mode

A

Maximum tolerable outage (MTO) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Overall intention and direction as formally expressed by management

A

Policy -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A document containing a detailed description of the steps necessary to
perform specific operations in conformance with applicable standards. Procedures are
defined as part of processes.

A

Procedure -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The remaining risk after management has implemented risk response

A

Residual risk -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A measure of operating performance and efficiency,
computed in its simplest form by dividing net income by the total investment over the
period being considered

A

Return on investment (ROI) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

An estimate of return on security investment

based on how much will be saved by reduced losses divided by the investment

A

Return on security investment (ROSI) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The combination of the probability of an event and its consequence. (ISO/IEC 73).
Risk has traditionally been expressed as Threats x Vulnerabilities = Risk

A

Risk -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly