Risk Identification Flashcards

1
Q

Risk

A

Is the potential for negative impact on the organization, its goals or objectives or assets(people, systems, and data) due to a threat exploiting a vulnerability.
Risk = Threat * Identification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk management

A

All the processes associated with identifying threats and vulnerabilities and quantifying and addressing the risk associated with those threats and vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat

A

A negative event that can lead to an undesirable outcome

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Examples of a threat

A

A hacker who wants to encrypt your data and charge you a ransom for it
A disgruntled employee who wants to steal or sell corporate information
A fire or other natural disaster that may damage or destroy your data center

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Vulnerability

A

Is a weakness or gap that exists within a system that may be exploited by a threat actor to compromise an asset security or trigger a risk event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Examples of vulnerabilities

A

Unpatched software applications
Weak access control mechanisms (weak passwords)
Faulty fire suppression system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Assets

A

Anything of value which includes people, property, and information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk Assessment

A

Is the set of activities that involves identifying the threat and vulnerabilities that exist and determining the impact and likelihood of those threats exploiting the identified vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Steps for assessing a risk

A

Risk identification
Risk analysis
Risk evaluation
Risk treatment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly