Risk Assessments and Treatments Flashcards
Risk Assessments and Treatments
strives to determine the likelihood and impact of threats
risk assessment
Risk Assessments and Treatments
environmental, personmade, internal, external
risk types
Risk Assessments and Treatments
security controls are proactively put in place before undertaking the risk
mitigation/reduction
Risk Assessments and Treatments
some risk is transferred to a third party in exchange for payment
i.e: cybersecurity insurance
Transference/sharing
Risk Assessments and Treatments
avoid an activity because the risks outweigh potential gains
Avoidance
Risk Assessments and Treatments
current level of risk is acceptable and falls within organization’s risk appetite
Acceptance