Risk Analysis & Ethics Flashcards
Risk Analysis
Focuses on the identification and understanding of risks
- Identify future events
- Identify the causes of the future events
- Understand and evaluate the consequences
Risk Evaluation
The process of assessing the severity and likelihood of a risk, determining how harmful it could be and how probable it is to occur.
(about figuring out how bad a risk could be and how likely it is to happen.)
Risk Assessment
Risk Analysis + Risk Evaluation
Parts of security management
Security Risk Assessment
(Threats / likelihood
Vulnerabilities / exploits
Assets / impact
Countermeasures)
Risk Mitigation
(Safeguard implement
Additional controls)
Operational Security
(Patches
Incident handling training)
Test & review
(Scanning
Audit controls)
What is Meta-ethics
What is goodness?
How to tell bad from evil?
Normative ethics
What should I do?
Virtue ethics
Deontology ethics
Consequentialism
Applied ethics
What should I do in this specific case?
Bioethics
Technology
Security & privacy
Explain the different disclosures
Full disclosure - posting it for all to see
Non-disclosure - don’t do anything
Coordinated disclosure - CVD policy on the receiving end
Informational self-determination
”The claim of individuals, groups and institutions to DETERMINE THEMSELVES, WHEN, HOW and TO WHAT EXTENT information about them is communicate to others”