Risk Assessment Flashcards
What are the three processes of risk?
Risk assessment
Risk mitigation
Evaluation and Assessment
How is risk calculated?
Threat * Vulnerability * Impact
What are the four categorisations of military risk?
Catastrophic
Critical
Marginal
Negligible
What is a threat tree?
Used in testing and auditing to find out where the weakest points are of a system.
What is SWOT?
Strengths
Weaknesses
Opportunities
Threats
What are system boundaries?
Good way of splitting up a major system into manageable parts
What are the limitations of system boundaries?
By separating out the experts some problems are localised and mitigated but some can get through boundaries.
What is the DREAD model for assessing threats?
Damage Potential Reproducibility Exploitability Affected Users Discoverability