Risk and Compliance Flashcards

1
Q

Reliable and timely access to data and resources is provided to authorized individuals

A

Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Accuracy and reliability of the information and

systems are provided and any unauthorized modification is prevented

A

Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Necessary level of secrecy is enforced and unauthorized disclosure is prevented

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Weakness or a lack of a countermeasure

A

Vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Entity that can exploit a vulnerability

A

Threat agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The danger of a threat agent exploiting a

vulnerability

A

Threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The probability of a threat agent exploiting a

vulnerability and the associated impact

A

Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Safeguard that is put in place to reduce a risk,

also called a countermeasure

A

Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Presence of a vulnerability, which exposes the organization to a threat

A

Exposure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

*Examples are: procedures, security documentation, risk management, personnel security, and training

A

Administrative Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

*Examples are: hardware/software mechanisms used to manage access. i.e. encryption, smart cards, passwords, biometrics, constrained interfaces, ACLs, protocols, firewalls, routers, IDS.

A

Logical/Technical Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

*Examples are: Barriers to prevent direct contact within facility. ie. guards, fences, motion detectors, locked doors, sealed windows.

A

Physical Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the below actions?

  • Accept
  • Avoid
  • Mitigate
  • Transfer
A

These are ways to manage risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Understand and proceed to take no action

A

Accept Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Change strategies and move in a different direction

A

Avoid Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Limit the impact of a risk, so that if it does occur, the problem it creates is smaller and easier to fix

A

Mitigate Risk

17
Q

Move the impact and management of the risk to others

A

Transfer Risk