M8: IT security management and risk assessment Flashcards
What is the main purpose of risk management in information security?
M8: IT security management and risk assessment
To help the organization’s leadership prioritize resources to manage risks effectively.
What does ISO-27001 define as a risk?
M8: IT security management and risk assessment
The effect of uncertainty on objectives, which can be positive or negative.
What are the five main activities in the risk management process?
M8: IT security management and risk assessment
- Context Establishment
- Risk assessment
- Risk treatment
- Risk acceptance
- Risk monitoring.
What is the first step in the risk management process?
M8: IT security management and risk assessment
Establishing the context of the organization.
What is risk assessment?
M8: IT security management and risk assessment
Identifying, analyzing, and evaluating risks based on the defined context.
What are the four options for risk treatment?
M8: IT security management and risk assessment
- Modify
- Accept
- Avoid
- Share
What is a risk treatment plan?
M8: IT security management and risk assessment
A plan that describes how identified risks will be managed.
Who is responsible for risk management in an organization?
M8: IT security management and risk assessment
The organization’s top management and the information security committee.
What is the role of the information security committee?
M8: IT security management and risk assessment
To approve and define the framework for risk management.
What is risk acceptance?
M8: IT security management and risk assessment
The decision to accept the risk without further action.
What is the purpose of risk monitoring?
M8: IT security management and risk assessment
To ensure that risk controls are implemented and effective.
What is a risk matrix?
M8: IT security management and risk assessment
A tool to illustrate the level of risk based on likelihood and impact.
What should be included in a risk treatment plan?
M8: IT security management and risk assessment
- Purpose
- Responsible person
- Resources
- Risk treatment actions
- Costs
- Timeline.
What is the significance of risk communication?
M8: IT security management and risk assessment
To create awareness about the risk profile and security efforts within the organization.
What is the importance of involving suppliers in risk management?
M8: IT security management and risk assessment
Suppliers have knowledge of technical solutions and controls that can affect risk