Random Flashcards

1
Q

What costs should be considered in a cost-benefit analysis?

A

Technology costs,
Opportunity costs,
Process impact costs,
Time costs,
Personnel costs,
Overall capability costs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the cost-of-loss formula to calculate an asset value?

A

K = Cp + Ct + Cr + Ci – I
K = total cost of loss
Cp = cost of permanent replacement
Ct = cost of temporary substitute
Cr = total related costs (remove old asset, install new, etc.)
Ci = lost income cost
I = available insurance or indemnity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How is security risk calculated for an individual asset?

A

Asset value rating X Threat likelihood rating X Severity of incident rating X Vulnerability rating = Security risk rating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

5 Major Areas in developing a BCP (Businesss Continuity Plan)

A

Phase 1
Preparedness/Readiness
Prevention
Response
Recovery

Phase 2
Testing, Training, Evaluating, & Maintenance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BCP Phase 1-Preparedness/Readines

A
  1. Assign accountability to a single individual
  2. Perform risk assessment
  3. Perform BIA
  4. Agree on strategic plans
  5. Form Crisis Managment Team
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

BCP Phase 1-Prevention

A
  1. Compliance w/corporate policy
  2. Mitigation strategies
  3. Avoidance, deterrence, detection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BCP Phase 1-Response

A
  1. Determine if there is a crisis
  2. Notify CMT
  3. Assess nature of situation
  4. Declare crisis
  5. Execute BCP
  6. Communicate to all appropriate parties
  7. Resourece Management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

BCP Phase 1-Recovery

A
  1. Damage and impact assessment
  2. Resumption of critical and remaining processes
  3. Return to normal operations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

BCP Phase 2-Testing, Training, Evaluating, and Maintenance

A
  1. Educating and training on the plan
  2. Testing the BCP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What four criteria can be used to rank assets based on criticality?

A

Workforce- # and type of workforce located onsite
Service delivery - % of overall service delivery that the asset is responsible for
Dependencies - importance of the asset to other assets
Mission/objectives - overall importance of the asset to the business mission or objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the technical criteria of the Security Metrics Evaluation Tool (Security MET)?

A

Reliability,
Validity,
Generalizability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the operational criteria of the Security Metrics Evaluation Tool (Security MET)?

A

Cost,
Timeliness,
Manipulation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the strategic criteria of the Security Metrics Evaluation Tool (Security MET)?

A

ROI,
Organizational relevance,
Communications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the evaluation criteria for the Security Metrics Evaluation Tool (Security MET).

A

Technical criteria,
Operational criteria,
Strategic criteria.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How is risk calculated?

A

Risk = (Threat x Vulnerability x Impact) / 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the two foundational design principles?

A

The Four Ds and Layered security (aka Defense in Depth)

17
Q

What equation is used for calculating risk when developing a design?

A

Risk = Vulnerability x Threat x Asset Value