Risk Flashcards
___ is a typically defined as the objective magnitude or amount of loss that an enterprise can tolerate without risking its continued existence
Risk Capacity
___ is typically defined as the amount of risk, on abroad level, that an enterprise or other entity is willing to accept in pursuit of its mission (or vision) and the achievement of business objectives
Risk appetite
What are the 3 line of defense of risk
1- Managing Risk
2-Guiding, directing, influencing and/or assessing Risk
3-Independent oversight, reviewing and monitoring risk.
What RACI means?
Responsible
Accountable
Consulted
Informed
Who's RACI to: collect risk data Senior Management Steering committee (chair) Department Managers Risk Practitioners
Senior Management - I
Steering committee (chair) - R
Department Managers - C
Risk Practitioners - R
Who's RACI to: Deliver the risk report (not use all) Senior Management Steering committee (chair) Department Managers Risk Practitioners
Senior Management - I
Steering committee (chair) - A
Department Managers - I
Risk Practitioners - R
Who's RACI to: Prioritize risk response Senior Management Steering committee (chair) Department Managers Risk Practitioners
Senior Management - A
Steering committee (chair) - I
Department Managers - R
Risk Practitioners -C
Who's RACI to: Monitor Risk Senior Management Steering committee (chair) Department Managers Risk Practitioners
Senior Management -I
Steering committee (chair) -A
Department Managers -R
Risk Practitioners -C
I&T related risk are because of:
Ownership Use Operation Involvement Influence Adoption
Type of I&T risk
Benefit/value enablement risk
Program and project delivery risk
IT operations and service-delivery risk
Cyberinformation security risk
IT RISK management workflow is
1-Conext settling
2-Identification of assets, common risk factor and documenting risk.
3-Assesment. Asses and prioritize risk creating risk scenarios
4-Analysis. Qualitive and quantitively analysis of impact and probability
5-Response and mitigation.
6-Monitoring, reporting and communicating to senior management.
The 3 level of risks are:
A)Operational
B)Program and project Risk of the bus strategic objectives
D)Strategic
Control Managerial (administrative) are
related to the oversight, reporting, procedures and operations of a process
Cyber and information security risk is related to
The danger, harm or loss related to the use of information and communications technology, electronic data and digital or electronic communications.
Exploit is
An event where the attacker takes advantages of a vulnerability