Risk Assessment Flashcards

1
Q

ISO 27001

A

Standard for managing information security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27002

A

Improve management of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO 27701

A

Privacy Information Management System (PIMS)

Establishing/implementing/maintaining/improving

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 31000

A

Managing risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SOC 2 Type 1

A

Assess design of security processes at specific point in time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SOC 2 Type 2

A

Assess security controls over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

EF

A

Exposure factor

% of value an asset lost due to incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SLE

A

Single loss expectancy

SLE = Asset Value (AV) x EV

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

NIST RMF Framework steps

A

Prepare

Categorize system

Select controls

Implement controls

Assess controls

Authorize system

Monitor controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly