Midterm Flashcards

1
Q

What is RPO?

A

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is RTO?

A

Recovery Time Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is MTD?

A

Maximum Tolerable Downtime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the three types of Control?

A
  • Technical Control
  • Administrative Control
  • Physical Control
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Risk Appetite?

A

The amount of risk a company is willing to accept depending depending on the objective

EXAMPLE
An organization might state that it has a “moderate” appetite for market expansion risks but a “low” appetite for compliance risks.
A tech company may have a high risk appetite for innovation and R&D investments but a low risk appetite for cybersecurity breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Risk Tolerance?

A

Example
Financial Risk: “We will not tolerate quarterly losses exceeding $500,000.”
Operational Risk: “We will accept a system downtime of up to 2 hours per month.”
Compliance Risk: “We have zero tolerance for regulatory non-compliance.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is CVSS?

A

Common vulnerability scoring system

  • Low (0-3.9)
  • Medium (4-6.9)
  • High (7-8.9)
  • Critical (9-10)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is CER?

A

Crossover Data Rate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is IT Risk?

A

Potential losses, Cybersecurity threats, data breaches, system failures etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the Measurability of IT Risk?

A

Quantitative Metrics, Qualitative Assessments, Risk Scores and Continuous monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Quantitative Metrics?

A

Number of incidents, financial losses from breaches, downtime duration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Risk Scores?

A

Combing qualitative and quantitative data which results in risk scores

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the FORMAL definition of risk?

A

Risk ($/year) = potential impact of an event on the business ($ amount of lost revenue) * estimates frequency of such events (# of events per year)

ALE (Annual Loss Expectancy) = SLE (Single Loss Expectancy) * ARO (Annualized Rate of Occurrence)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is SLE?

A

Single Loss Expectancy - defined as a dollar amount that is assigned to a single event that represents the companies potential loss amount if a specific threat were to take place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is ARO?

A

Annualized Rate of Occurrence - value that represents the estimates frequency of a specific threat taking place within a 12- month period. For example, ARO = 2, means event takes place twice a year; ARO = 0.5, means event takes place once for every two years; ARO = 0, means event wont happen at all

17
Q

What is ERM (Enterprise Risk Management)?

A
  • Process effected by an entitys board of directors, management and other personnel
  • Risk appetite is defined by COSO as “the amount of risk, on a broad level that an organization is willing to accept in pursuit of its business objectives.
18
Q

What are key benefits following common framework for managing enterprise risks?

A
  1. Adopt a common risk language
  2. Conduct an enterprise risk assessment to identify and prioritize the organizations critical risks
  3. Perform a gap analysis of the current and target capabilities around managing the critical risks
  4. Make informed business decisions at all levels of an organization using a repeatable process
  5. Align risk management effort with company’s vision, goals and objectives
19
Q

What are the KEY elements of an ERM (Enterprise Risk Management) framework?

A

Business Strategy <-> Risk Culture - > Risk Governance, Risk Universe, Risk Management Policies, Risk Appetite -> Identify, Measure, Manage, Monitor, Report

20
Q

What is a KRI?

A

Key Risk indicators - a metric used by organizations to provide an early signal of increasing risk exposures in various areas of the enterprise

21
Q

Leading indicators VS lagging indicators

A

Leading indicators (PROACTIVE) - leading indicators identify emerging trends for risks and enable management to take proactive steps to prevent events from occuring

Lagging indicators (DETECTIVE) - Lagging indicators may be considered “detective” in nature and provide information about events that have occurred in the past

22
Q

3 LOD ( Line of Defence) to manage IT risks?

A

1st Line of defence - business and IT functions
2nd Line of defence - Information and technology risk management functions
3rd Line of defence - Internal Audit

23
Q

What are some key challenges for the 3 lines of defense model?

A
  1. May require change of exisiting business processes
  2. Lack of awareness or education for the first line staff
  3. Can be expensive to operate
24
Q

What can be considered when tasked with designing an IT risk management framework form scratch

A
  1. Companys existing framework or processes for risk management
  2. level of maturity for risk managing and the companys overall awareness about risk management
  3. Competitive landscapeof the industry in which the company operates
25
Q
A