Risk Assessment Flashcards
1
Q
Define Risk Assessment
A
- An evaluation of how much risk you and your organization are willing to take on.
- Must be performed before any other action, such as how much to spend on security and manpower.
2
Q
Vulnerability
A
A weakness that could be exploited by a threat.
3
Q
Key Components of Risk Assessent
A
- Risks to Which the Organization is exposed.
- Develop scenarios that can help you evaluate how to deal with risks.
- Risks that need addressing.
- Determine which risks need addressing and which ones are unlikely. Allows you to focus resources.
- Coordination with BIA (Business Impact Analysis)
- Provides the organization with an accurate picture of the situation facing it.
4
Q
ALE
A
- Annual Loss Expectancy value.
- Risk Calcualation
- The MONETARY measure of how much loss you could expect in a year.
5
Q
SLE
A
- Single Loss Expectancy
- MONETARY measure of how much loss you could expect in a year.
- Two Components
- AV - Asset Value
- EF - Exposure Factor
6
Q
ARO
A
- Annualized Rate of Occurrence
- Likelihood, often drawn from historical data, of an event occuring within one year.
7
Q
Comput Risk Assessment Formula
A
SLE * ARO = ALE
8
Q
Quantitative Risk Assessement
A
- Cost-based.
- Objective.
- Focused on dollar amounts.
9
Q
Qualitative
A
- Opinion-based.
- Subjective
10
Q
Likelihood
A
- NIST recomments viewing Likelihood as a score representing the possibility of threat initiation.
- Can be expressed in either quantitative or qualitative terms.
11
Q
Threat Vectors
A
- The WAY in which an attacker poses a threat.
- Tool used.
- Path used.
- Examples
- Fake email that lures you into clicking a link (Phishing).
- Unsecured wifi hotspot.
12
Q
Mean Time Between Failures
A
- MTBF
- Meaures of the anticipated incidence of failure for a system or component.
- Determines the component’s anticipated lifetime.
- Helpful in evaluating a system’s reliability and life expectancy.
13
Q
Mean Time to Failure
A
- MTTF
- Average time to failure for a NON-REPAIRABLE system.
- Only use if system cannot be repaired.
- If the system can be repaired, use Mean Time Between Failures (MTBF).
14
Q
Mean Time to Restore
A
- MTTR
- Measure of how long it takes to repair a system or component once a failure occurs.
15
Q
Recovery Tome Objective
A
- RTO
- Maximum amount of time the process or service is allowed to be down and the consequences still be considered acceptable.
- Agreed on during BIA creation.