Risk Graphs and tools Flashcards

1
Q

What are the three kinds of Threat Trees?

A

1) Asset Tree-asset, means of access, internal or external threat actor, intentional or unintentional motive, capability, event, consequence
2) Threat type tree-Type of threat, act, resultant effect, consequence
3) Adversary tree-adversary type, motivation, capability, methods, event, consequences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Picture the Risk Toleration Funnel, How is it used?

A

It is used to filter risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Picture a risk frontier Graph. How is it used?

A

It is used to determine if it is more effective to reduce the potential loss/seriousness of consequence or decrease the likelihood of the risk occurring to achieve the desired “Acceptable Risk” frontier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Picture the Level of Risk Analysis Flowchart.

A

xxx

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the main drawback to automated tools?

A

They are not good at assessing intangible factors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an event Tree?

A

A tree that traces an initiating event through a sequence with different possible outcomes. Uses inductive logic to infer results.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Fault Tree?

A

Often used with Event trees to determine the base causes of an event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly