Module 2: Cybersecurity & the Business Flashcards
Define ‘Risk’ in the context of cybersecurity.
A measure of the extent to which an entity is threatened by a potential circumstance or event, typically considering the adverse impacts and likelihood of occurrence.
What is ‘Residual Risk’?
Residual Risk refers to the portion of risk remaining after security measures have been applied.
What is the purpose of the ‘Govern’ phase in the NIST Cybersecurity Framework?
Covers people, process, and technology elements, including roles, responsibilities, policies, procedures, and oversight, in addition to technology.
What is the purpose of the ‘Identify’ phase in the NIST Cybersecurity Framework?
Involves asset management, business environment, governance, risk assessment, and risk management strategy.
What is the purpose of the ‘Protect’ phase in the NIST Cybersecurity Framework?
Focuses on access control, awareness training, data security, information protection processes, and protective technology.
What is the purpose of the ‘Detect’ phase in the NIST Cybersecurity Framework?
Involves detecting anomalies and events, continuous security monitoring, and establishing detection processes.
What is the purpose of the ‘Respond’ phase in the NIST Cybersecurity Framework?
Includes response planning, communications, analysis, mitigation, and improvements after detecting a security incident.
What is the purpose of the ‘Recover’ phase in the NIST Cybersecurity Framework?
Focuses on recovery planning, communication, and improvement after an incident to return to normal operations.
What are the six phases of the NIST Cybersecurity Framework?
Govern, Identify, Protect, Detect, Respond, Recover