Risk Identification Flashcards
Risk
Is the potential for negative impact on the organization, its goals or objectives or assets(people, systems, and data) due to a threat exploiting a vulnerability.
Risk = Threat * Identification
Risk management
All the processes associated with identifying threats and vulnerabilities and quantifying and addressing the risk associated with those threats and vulnerabilities
Threat
A negative event that can lead to an undesirable outcome
Examples of a threat
A hacker who wants to encrypt your data and charge you a ransom for it
A disgruntled employee who wants to steal or sell corporate information
A fire or other natural disaster that may damage or destroy your data center
Vulnerability
Is a weakness or gap that exists within a system that may be exploited by a threat actor to compromise an asset security or trigger a risk event
Examples of vulnerabilities
Unpatched software applications
Weak access control mechanisms (weak passwords)
Faulty fire suppression system
Assets
Anything of value which includes people, property, and information
Risk Assessment
Is the set of activities that involves identifying the threat and vulnerabilities that exist and determining the impact and likelihood of those threats exploiting the identified vulnerabilities.
Steps for assessing a risk
Risk identification
Risk analysis
Risk evaluation
Risk treatment