Questions Flashcards
1
Q
4 Different Threat Categories
A
- Adversarial
- Accidental
- Structural
- Environmental
(Chap 1)
2
Q
What things should you consider when assessing risk?
A
You should assess the likelihood that a risk will materialize (that the risk will occur or that the threat source will initiate the risk) and the impact that the risk will have on the organization if it does occur. If a risk occurs, will it actually have an adverse impact on the CIA of an organization?
3
Q
What are common risk management strategies?
A
- Risk acceptance
- Risk avoidance
- Risk mitigation
- Risk transference
4
Q
What is a common way that organizations manage security risks?
A
They develop sets of technical and operational security controls that mitigate those risks to acceptable levels.