Module 2 Flashcards
An asset
Anything of value that is owned by an organization. It is something in need of protection.
A vulnerability
Weakness in an information system, system security procedures, internal controls or implementation that could be exploited by a threat source.
A threat
Any circumstance or event with the potential to adversely impact organizational operations
Something or someone that aims to exploit a vulnerability to thwart protection efforts.
Risk assessment
Is defined as the process of identifying , estimating and prioritizing risks to an organization’s operations( including its mission, functions, image and reputation), assets, individuals, other organizations and even the nation.
Risk treatment
Relates to making decisions about the best actions to take regarding the identified and prioritized risk.
The four options to commonly used to respond to risk are :
1.Acceptance
Risk acceptance is taking no action to reduce the likelihood of a risk occurring.
- Transfer
Risk transference is the practice of passing the risk to another party, who will accept the financial impact of the harm resulting from a risk being realized in exchange for payment.
3.Mitigation
Risk mitigation is the most common type of risk management and includes taking actions to prevent or reduce the possibility of a risk event or it’s impact.
Mitigation can involve remediation measures, or controls, such as security controls, establishing policies, procedures and standards to minimize adverse risk.
4.Avoidance
Risk avoidance is the decision to attempt to eliminate the risk entirely. This could include ceasing operation for some or all of the activities of the organization that are exposed to particular risk.
Qualitative Risk analysis
A method for risk analysis that is based on the assignment of a descriptor such as low, medium or high.
Quantitative risk analysis
A method for risk analysis where numerical values are assigned to both impact and likelihood based on statistical probabilities and monetarized valuation of loss or gain.
Risk Tolerance
The level of risk an entity is willing to assume in order to achieve a potential desired result.