PSP FLASHCARDS
A management process that ties an organization’s security practice to its overall protection strategy using globally established risk management principles to manage risk where asset owners own decisions for the risks to assets they manage. (POA PS, page 1).
Enterprise security risk management (ESRM).
Who in ESRM is responsible for identifying, prioritizing, and developing remediation efforts for assets at risk? (POA PS, page 2).
Asset owners in partnership with the security professional.
An enterprise risk program that typically focuses on all aspects of organizational risk such as financial, operational, and strategic. (POA PS, page 2).
Enterprise risk management (ERM).
What are the three components of ESRM?
(POA PS, page 5).
- The context.
- The Foundation.
- The ESRM cycle
What component of the ESRM is critical for the security professional to not only understand the various threats that may impact the organization but to also understand the organization itself? (POA PS, page 5).
Context
A critical requirement for the successful ESRM adoption strategy in the risk management process of an organization. (POA PS, page 5).
Align the security strategy and the organization’s overall strategy.
What are the two elements that are considered to be the pinnacle of organizational strategy? (POA PS, page 5).
- Mission
- Vision
What are the five core values of an organization? (POA PS, page 6).
- Environmental stewardship
- The community
- Employee safety and security
- Product quality; &
- Brand and image protection
What often defines and organization’s culture? (POA PS, page 7).
Core values
For the security professional to effectively assess risk and build relationships, he/she must understand the operating environment in which the organization functions. What are the three elements that form the operating environment?
- Physical.
- Non-physical.
- Logical.
What are some of the physical environment key factors a security professional should understand to effectively evaluate and prioritize risk and partner with asset owners?
- Type of location.
- Building and surrounding environment.
- Pedestrian/ vehicle traffic in the area.
- Non-employees who require access.
- Industrial control systems.
- Criticality and sensitivity of processes and assets on site.
- Products on hand and warehoused.
What are some of the nonphysical key factors that asset owners and security professionals must understand to effectively evaluate and prioritize risks and develop risk mitigation measures for an organization? (POA PS, page 7).
- Geo-political environment.
- External pressures on the industry.
- Legal/regulatory/compliance requirements.
- Intensity of the competition.
- Growth mode of the organization.
- Speed required for decision-making.
- Impact of technology.
- Ongoing change including leadership
What are some of the logical factors that asset owners and security professionals must understand to effectively evaluate and prioritize risks and develop mitigation measures for an organization? (POA PS, page 8).
Digital assets and networks that connect them to each other and other stakeholders
Businesses and industries heavily rely on digital connections and data for all phases of their operations. Provide examples of these logical factors. (POA PS, page 8).
- Servers.
- Workstations.
- Network infrastructure.
- Connectivity
Why do stakeholders matter in the ESRM risk management process and what role does the security professional play? (POA PS, page 8).
- They are essentially the risk decision-makers.
- The security professional must know what is important to the stakeholders and assist them in formulating mitigation strategies for security-related risks.