Risk Management Flashcards

1
Q

BIA

A

Business Impact Analysis

Evaluates effects of disruptions on business functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RPO

A

Recovery Point Objective

○ Maximum acceptable data loss measured in time
○ Point in time data must be restored to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

MTTR

A

Mean Time To Repair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

MTBF

A

Mean Time Between Failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Register

A

Records identified risks, descriptions, impacts, likelihoods, and mitigation actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk Tolerance/Risk Appetitie

A

Willingness to pursue or retain risk.

Expansionary, Conservative or Neutral

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

KRIs

A

Key Risk Indicators

Predictive metrics signaling increasing risk exposure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk Owner

A

Responsible for managing the risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Qualitative Risk Analysis

A

Assesses risk based on potential impact and likelihood. Subjective and relies on expertise and experience

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quantitative Risk Analysis

A

Provides objective and numerical evaluation of risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

EF

A

Exposure Factor

Proportion of asset lost in an event (0-100%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SLE

A

Single-Loss Expectancy

Monetary value expected to be lost in a single event.

Asset Value x Exposure Factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ARO

A

Annualized Rate of Occurrence

Estimated yearly frequency of risk incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ALE

A

Expected annual loss from a risk

SLE x ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Risk Transference

A

Shift risk to another party (insurance, contract idemnity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk Acceptance

A

Acknowledge and deal with risk if it occurs.

Used when managing the risk outweighs potential loss

17
Q

Risk Avoidance

A

Change plan or strategy to eliminate a risk

Chosen when the risk is too great to accept or transfer

18
Q

Risk Mitigation

A

Take steps to reduce likelihood or impact of risk

19
Q

Residual Risk

A

Likelihood after mitigation, transference or acceptence

20
Q

Control Risk

A

Assessment of how a security measure has lost effectiveness over time

21
Q

CHIPS Act of 2022

A

■ U.S. federal statute providing funding to boost semiconductor research and
manufacturing in the U.S.
■ Aims to reduce reliance on foreign-made semiconductors, strengthen the domestic supply chain, and enhance security

22
Q

MSP

A

Managed Service Provider

Manage IT services on behalf of organizations

23
Q

Right-to-Audit clause

A

Contract provision allowing organizations to evaluate vendor’s internal processes
for compliance

24
Q

Vendor Questionnaire

A

Comprehensive documents filled out by potential vendors

Provide insights into operations, capabilities, and
compliance

25
Q

Rules of Engagement

A

Guidelines for interaction between organization and vendors

26
Q

Vendor Monitoring

A

Mechanism used to ensure that the chosen vendor still aligns with organizational
needs and standards

27
Q

SLA

A

Service Level Agreement

Defines the standard of service a client can expect from a provider.
Includes performance benchmarks and penalties for deviations

28
Q

MOA

A

Memorandum of Agreement

Formal, outlines specific responsibilities and controls

29
Q

MOU

A

Memorandum of Understanding

Less binding than MOA. Expresses mutual intent without specifics.

30
Q

MSA

A

Master Service Agreement

Covers general terms of engagement across multiple transactions

31
Q

SOW

A

Statement of Work

Specifies project details, deliverables, timelines, and milestones. Provides in-depth project-related information

32
Q

NDA

A

Non-Disclosure Agreement

Ensures confidentiality of sensitive information shared during
negotiations

33
Q

BPA or JVA

A

Business Partnership Agreement or Joint Venture Agreement

● Goes beyond basic contracts when two entities collaborate
● Outlines partnership nature, profit-sharing, decision-making, and exit
strategies
● Defines ownership of intellectual property and revenue distribution