Random Flashcards
What costs should be considered in a cost-benefit analysis?
Technology costs,
Opportunity costs,
Process impact costs,
Time costs,
Personnel costs,
Overall capability costs.
What is the cost-of-loss formula to calculate an asset value?
K = Cp + Ct + Cr + Ci – I
K = total cost of loss
Cp = cost of permanent replacement
Ct = cost of temporary substitute
Cr = total related costs (remove old asset, install new, etc.)
Ci = lost income cost
I = available insurance or indemnity
How is security risk calculated for an individual asset?
Asset value rating X Threat likelihood rating X Severity of incident rating X Vulnerability rating = Security risk rating
5 Major Areas in developing a BCP (Businesss Continuity Plan)
Phase 1
Preparedness/Readiness
Prevention
Response
Recovery
Phase 2
Testing, Training, Evaluating, & Maintenance
BCP Phase 1-Preparedness/Readines
- Assign accountability to a single individual
- Perform risk assessment
- Perform BIA
- Agree on strategic plans
- Form Crisis Managment Team
BCP Phase 1-Prevention
- Compliance w/corporate policy
- Mitigation strategies
- Avoidance, deterrence, detection
BCP Phase 1-Response
- Determine if there is a crisis
- Notify CMT
- Assess nature of situation
- Declare crisis
- Execute BCP
- Communicate to all appropriate parties
- Resourece Management
BCP Phase 1-Recovery
- Damage and impact assessment
- Resumption of critical and remaining processes
- Return to normal operations
BCP Phase 2-Testing, Training, Evaluating, and Maintenance
- Educating and training on the plan
- Testing the BCP
What four criteria can be used to rank assets based on criticality?
Workforce- # and type of workforce located onsite
Service delivery - % of overall service delivery that the asset is responsible for
Dependencies - importance of the asset to other assets
Mission/objectives - overall importance of the asset to the business mission or objective
What are the technical criteria of the Security Metrics Evaluation Tool (Security MET)?
Reliability,
Validity,
Generalizability.
What are the operational criteria of the Security Metrics Evaluation Tool (Security MET)?
Cost,
Timeliness,
Manipulation.
What are the strategic criteria of the Security Metrics Evaluation Tool (Security MET)?
ROI,
Organizational relevance,
Communications.
What are the evaluation criteria for the Security Metrics Evaluation Tool (Security MET).
Technical criteria,
Operational criteria,
Strategic criteria.
How is risk calculated?
Risk = (Threat x Vulnerability x Impact) / 3