Risk Assesment Flashcards

1
Q

What is Risk Assessment in security?

A

The process used to identify how much risk exists in a network or system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Risk?

A

The probability that a threat will occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are Vulnerabilities?

A

A weakness in the design or implementation of a system. Vulnerabilities are within your control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Threat?

A

Any condition that could cause harm, loss, damage or compromise in our IT systems. They are external sources such as natural disasters, cyber attackers, data breaches, discloser of confidential information, issues that may arise during daily operations. Threats are external and beyond your control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What can we do about risk?

A

There are a few general strategies.

Risk Avoidance is a strategy that requires you to stop the activity with risk or choosing a less risky alternative.

Risk Mitigation is a strategy that seeks to minimize the risk to an acceptable level.

Risk Transfer to a third party, insurance usually.

Risk Acceptance is a strategy that accepts the risks because of the cost/benefit analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Residual Risk?

A

The remaining risk after trying to avoid, transfer, or mitigate the risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do you conduct a risk assesment?

A

Identify Assets
Identify Vulnerabilities (Vulnerability Assessment, Vulnerability Scan, Penetration Test)
Identify Threats
Identify the Impact of the risks occurring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly