Midterm Flashcards
What is RPO?
Recovery Point Objective
What is RTO?
Recovery Time Objective
What is MTD?
Maximum Tolerable Downtime
What are the three types of Control?
- Technical Control
- Administrative Control
- Physical Control
What is a Risk Appetite?
The amount of risk a company is willing to accept depending depending on the objective
EXAMPLE
An organization might state that it has a “moderate” appetite for market expansion risks but a “low” appetite for compliance risks.
A tech company may have a high risk appetite for innovation and R&D investments but a low risk appetite for cybersecurity breaches.
What is a Risk Tolerance?
Example
Financial Risk: “We will not tolerate quarterly losses exceeding $500,000.”
Operational Risk: “We will accept a system downtime of up to 2 hours per month.”
Compliance Risk: “We have zero tolerance for regulatory non-compliance.”
What is CVSS?
Common vulnerability scoring system
- Low (0-3.9)
- Medium (4-6.9)
- High (7-8.9)
- Critical (9-10)
What is CER?
Crossover Data Rate
What is IT Risk?
Potential losses, Cybersecurity threats, data breaches, system failures etc.
What are the Measurability of IT Risk?
Quantitative Metrics, Qualitative Assessments, Risk Scores and Continuous monitoring
What is Quantitative Metrics?
Number of incidents, financial losses from breaches, downtime duration
What is Risk Scores?
Combing qualitative and quantitative data which results in risk scores
What is the FORMAL definition of risk?
Risk ($/year) = potential impact of an event on the business ($ amount of lost revenue) * estimates frequency of such events (# of events per year)
ALE (Annual Loss Expectancy) = SLE (Single Loss Expectancy) * ARO (Annualized Rate of Occurrence)
What is SLE?
Single Loss Expectancy - defined as a dollar amount that is assigned to a single event that represents the companies potential loss amount if a specific threat were to take place