Lot 5 Flashcards
A subset of risk indicators that are highly relevant and
possess a high probability of predicting or indicating important risk
Key risk indicator (KRI) -
The principle of allowing users or applications the least amount of
permissions necessary to perform their intended function
Least privilege -
A means of restricting access to data based on
varying degrees of security requirements for information contained in the objects and the
corresponding security clearance of users or programs acting on their behalf
Mandatory access control (MAC) -
Maximum time the organization can support
processing in alternate mode
Maximum tolerable outage (MTO) -
Overall intention and direction as formally expressed by management
Policy -
A document containing a detailed description of the steps necessary to
perform specific operations in conformance with applicable standards. Procedures are
defined as part of processes.
Procedure -
The remaining risk after management has implemented risk response
Residual risk -
A measure of operating performance and efficiency,
computed in its simplest form by dividing net income by the total investment over the
period being considered
Return on investment (ROI) -
An estimate of return on security investment
based on how much will be saved by reduced losses divided by the investment
Return on security investment (ROSI) -
The combination of the probability of an event and its consequence. (ISO/IEC 73).
Risk has traditionally been expressed as Threats x Vulnerabilities = Risk
Risk -