Risk Assessment Flashcards
1
Q
ISO 27001
A
Standard for managing information security
2
Q
ISO 27002
A
Improve management of information
3
Q
ISO 27701
A
Privacy Information Management System (PIMS)
Establishing/implementing/maintaining/improving
4
Q
ISO 31000
A
Managing risk
5
Q
SOC 2 Type 1
A
Assess design of security processes at specific point in time
6
Q
SOC 2 Type 2
A
Assess security controls over time
7
Q
EF
A
Exposure factor
% of value an asset lost due to incident
8
Q
SLE
A
Single loss expectancy
SLE = Asset Value (AV) x EV
9
Q
NIST RMF Framework steps
A
Prepare
Categorize system
Select controls
Implement controls
Assess controls
Authorize system
Monitor controls