RISK MANAGEMENT Flashcards
Risk
Risk is a measure of the extent to which an entity is threatened by a potential circumstance or event.
It is often expressed as a combination of:
1.the adverse impacts that would arise if the circumstance or event occurs, and
2.the likelihood of occurrence.
Information Security Risk
Information security risk reflects the potential adverse impacts that result from the possibility of unauthorized access, use, disclosure, disruption, modification or destruction of information and/or information systems.
Threat
Threat is something or someone that aims to exploit a vulnerability to gain unauthorized access.
Asset
An asset is something in need of protection.
Likelihood of occurance
Likelihood of occurrence is a weighted factor based on a subjective analysis of the probability that a given threat or set of threats is capable of exploiting a given vulnerability or set of vulnerabilities.
Impact
Impact is the magnitude of harm that can be expected to result from the consequences of unauthorized disclosure of information, unauthorized modification of information, unauthorized destruction of information, or loss of information or information system availability.
Risk Assesment
Risk assessment is defined as the process of identifying, estimating and prioritizing risks to an organization’s operations
Risk Treatment
Risk treatment relates to making decisions about the best actions to take regarding the identified and prioritized risk.
Risk Avoidance
Risk avoidance is the decision to attempt to eliminate the risk entirely.This could include ceasing operation for some or all of the activities of the organization that are exposed to a particular risk.
Organizational leadership may choose risk avoidance when the potential impact of a given risk is too high or if the likelihood of the risk being realized is simply too great.
Risk Management
Risk acceptance is taking no action to reduce the likelihood of a risk occurring.
Management may opt for conducting the business function that is associated with the risk without any further action on the part of the organization, either because the impact or likelihood of occurrence is negligible, or because the benefit is more than enough to offset that risk.
Risk Transferance
Risk transference is the practice of passing the risk to another party, who will accept the financial impact of the harm resulting from a risk being realized in exchange for payment. Typically, this is an insurance policy.
Risk Mitigation
Risk mitigation is the most common type of risk management and includes taking actions to prevent or reduce the possibility of a risk event or its impact.
Mitigation
Taking action to reduce or prevent the impact of an event
Acceptance
Ignoring the risk and continuing risky activities
Avoidance
Ceasing the risky activity to remove the likelihood that an event will occur