Preparing for the activities Flashcards
What will help identify the risk severity of the attack (Activity 1)
Risk matrix
When explaining the risks, it should be done with what in mind? (Activity 1)
Context of the scenario
How many threats should be addressed by one protection measure (Activity 2)
As many as possible
What will help justify the mitigation methods (Activity 2)
An explanation on the reasons for taking the actions
What constraints should be considered when writing a protection measure (Activity 2)
The technical and financial constraints
What responsibilities should be considered when writing the mitigations (Activity 2)
The legal responsibilities
How will the mitigation affect the system? (Activity 2)
The mitigations will potentially affect the usability and accessibility of the system
What analysis should help justify the protection measure (Activity 2)
Cost- Benefit Analysis
What should be analysed when reviewing the evidence detail (Activity 4)
Analysis of what the evidence does and does not present against the scenario
What about the source of the evidence should be considered? (Activity 4)
The reliability
Should individual evidence items be considered against each other
No - Only write a conclusion for one evidence item at the end
What should the final conclusion include? (Activity 4)
The evidence presented in each analysis to form a narrative
List the 3 steps for activity 5
Adherence to company policy, how the policy can be improved, general weaknesses and omissions from the policy