Risk Flashcards
What is Risk?
Possibility of a threat exploiting a vulnerability
What is technical control?
Technology security i.e 802.11i
What is management control?
Risk/vulnerability assessment
Written security policy
Mandatory vacation
What is operational control?
Change management/procedure
Ensure day-to-day operations comply with security policy
What is a false positive?
IPS/IDS recoginises malicious trraffic when there isn’t
What is a false negative?
IPS/IDS fails to recognise malicious traffic
What is mandatory vacation?
Can reduce collusion and fraud of employees
How is separation of duties more secure?
Developer creates application
Team implements software (i.e possible backdoor in software for dev)
What is SLE?
Single loss expectancy
What is ARO?
Annualised Rate of Occurrence
i.e 5 year failure 1/5 = 0.2 ARO
What is ALE?
Annualised Loss Expectancy
ALE = SLE * ARO
What is a Software escrow
Source code of application available via provider company in event application is no longer supported
What is MTTR?
Mean Time to Restore
What is MTTF?
Mean Time to Failure
regarding non-repairable systems
What is MTBF?
Mean Time Between Failure