Risk Analysis Flashcards

1
Q

Risk analysis vocab

A

Risk register: formal documentation of risk in the organization
Risk Matrix: Heat map of risk vs probability/likelihood
Risk control assessment/ self Assessment: a review of vulnerabilities that could risk the organization
Risk Awareness: awareness training for employee
Risk appetite: how much risk you are ok with as a organization
Inherent risk: Risk already within the network
Residual risk: ongoing risk and to monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Quantitatuve risk assessent?

A

Quantitative - measures of economic impact of the risk measured and observered and the controls to mitigate them

Annualized Loss expentancy (ALE) = Single loss expectancy (SLE) * Annual rate Occurrence (ARO)

SLE = assest value * exposure factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SLE = assest value(AV) * exposure (eF)

A

Assest value (AV) - $$$ amount assest is worth to the oranization

Exposure Factor (EF) - % of loss experienced IF a specific assest were attacked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ALE = SLE *ARO

A
ALE = \_\_\_\_\_
SLE = \_\_$10.00\_\_($100*10%)
ARO = 10
  1. Countermeasure is less than ALE Do this
  2. Countermeasure is equal to ALE DO this
  3. Countermeasure is greater than ALE Think before acting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is qualitative risk assessmnt?

A

Qualitative - measure “tangibles” The product of likelihood and impacy produces the level of risk.

The higher the risk level, the more immediate the need for the organiztion to address the issure. (Risk Matrix)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly