Risk Management Flashcards

1
Q

WHAT IS RISK MANAMENT

A

KEEP UP WITH RISK BY LOOKING REPORTING PATCHING ETC.
`\

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RISK ANALYSIS

A

LIST OF RISK THAT CAN HELP YOU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

RISK TREATMENT

A

HELP MANAGING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

RISK ASSESSMENT FREQUENCE

A

HOW OFTEN THE RISK ASSESSMENT IS CONDUCTED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AD-HOC

A

CONDUCTED WHEN AND AS NEEDED TO A SPECIFIC EVENT THAT CAN INTRODUCE NEW RISK OR CHANGE. NATRUAL DIASTER

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

RECURRING RISK ASSESSMENT

A

MONTHLY,ANNUALLY OR QUARTERLY ANALYSIS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ONE TIME RISK ASSESSMENT

A

NOT REPEATED FOR PROJECTS OR USING NEW IT SYSTEMS JUST HAPPENS ONE TIME.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CONTINUOUS RISK ASSESSMENTS

A

ON GOING MONITOR AND EVAL ON RISK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RISK IDENTIFICIATION

A

RECOGNIZING POTENITAL RISK THAT COULD IMPACT ORG’S

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

BUSINESS IMPACT ANALYSIS

A

EVALUATING POTENTIAL EFFECTS OF DISRUPTION TO AN ORG BUSINESS FUNCTIONS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

RTO-RECOVERY TIME OBJECTIVE

A

REPRESENTS THE MAX ACCEPTABLE LENGTH OF TIME. BEFORE THE LACK OF A BUSINESS FUNCTION GETS REALLY IMPACTED.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

RECOVERY POINT OBJECTIVE-RPO

A

MAX ACCEPTABLE AMOUNT OF DATA LOSS IN MEASURED TIME.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

MTTR MEAN TIME TO REPAIR-MMTR

A

AVERAGE TIME REQUIRED TO REPAIR A FAILED COMPONENT OR SYSTEM.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

MEANT TIME BETWEEN FAILURES MTBF

A

AVERAGE TIME BETWEEN FAILURES.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

RISK REGISTER

A

A DOCUMENT RECORDS DEATILS OF THE RISK SUCH AS WHAT AND HOW IT HAPPENED.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

RISK DESCRIPTION

A

DEATILING WHAT THE RISK IS DESCRIPTION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

RISK IMPACT

A

THE CONSEQUENCES IF THE RISK TAKES PLACE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

RISK LIKELIHOOD

A

CHANCE OF THE RISK HAPPENING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

RISK OUTCOME

A

IF RISK HAPPENS WHAT IS THE RESULT OF IT

20
Q

RISK LEVEL

A

COMBINING IMPACT AND LIKELIHOOD

21
Q

THE COST OF RISK

A

COST OF MITAGTING/HAPPENING RISK.

22
Q

RISK TOLERANCE

A

THE ORG IS WILLING TO ACCEPT THE RISK

23
Q

RISK APPETITIE

A

AN ORG WILLING TO EMBRACE SPECIFIC TYPES OF RISK.

24
Q

EXPANSIONARY RISK APPETITIE

A

ORG IS TAKING MORE RISK TO GETTER LARGER RETURNS

25
Q

CONSERVATIVE RISK APPETITIE

A

FAVORS LESS RISK

26
Q

NEUTRAL RISK APPETITITE

A

BALANCE OF RISK AND RETURN.

27
Q

KEY RISK INDICATORS

A

PREDICTIVE METRICS TO SIGNAL RISING RISK LEVELS IN DIFFERENT PARTS OF THE ENTERPRISE.

28
Q

RISK OWNER

A

PERSON OR GROUP IN CHARGE OF TAKING RESPOINIBTY OF THE RISK

29
Q

QUALTIVITE RISK ANALAYSIS

A

METHOD OF ASSESSING RISK BASED ON THE IMPACT AND LIKELIHOOD OF THEM HAPPENING.

30
Q

EXPOSURE FACTOR

A

PROPORTION OF AN ASSET THAT IS LOST.

31
Q

SINGLE LOSS EXPECTANCTY SLE

A

MONETERY VALUE EXPECTED TO BE LOST IN A SINGLE EVENT

32
Q

ANNUALIZED RATE OF OCCURRENCE

A

ESTIMATED FREQUENCY WITH WHICH A THREAT IS EXPECTED TO OCCUR IN A YEAR.

33
Q

ANNUALIZED LOSS EXPECTANCY

A

SLE x ARO annual lost from a risk

34
Q

RISK MANAGMENT STRATS

A

-RISK TRANSFERENCE SHIFTING RISK TO ANOTHER PARTY
-RISK ACCEPTANCE- DEALING WITH A RISK IF IT OCCURS BASICALLY WHEN IT ARISES.
-EXEMPTION- EXCLUDES PARTY FROM A SPECIFIC RULE OR REQUIRMENT.
EXCEPTION- PERMITS PARTY TO BY PASS A RULE OR REQUIRMENT.

35
Q

RISK AVOIDANCE

A

PLANS TO COMPLETELY AVOID THE RISK

36
Q

RISK MITIGATION

A

STEPS TO TAKE TO DECRESE LIKELIHOOD THE RISK.

37
Q

RISK MONITORING

A

TRACKING IDENTIFIED ASSESSING EXECUTING RESPONSE ACTION ON A RISK

38
Q

RESIDUAL RISK

A

IMPACT AFTER IMPLMENTNG MITAGAION

39
Q

CONTROL RISK

A

HAS LOST EFFECTIVENESS OVER TIME.

40
Q

RISK REPORTING

A

COMMUNICATION INFO ABOUT RISK MANAGEMENT ACTIVITIES.

41
Q

INFORMED DECISION MAKING

A

INSIGHTS FOR INFORMED DECISIONS ON RESORVCE ALLOACATIONI

42
Q

RISK MITIGATION

A

WHEN A RISK ESCLATIONG TO MITIAGETE THE RISK BEFORE IT BECOMES A PROBLEM

43
Q

STAKEHOLDER COMM

A

SETTING EXPECTIONS AND SHOWING EFFECTIVE RISK MANANGMENT

44
Q

REGULATORY COMPLIANCE

45
Q

SLE

A

The Single Loss Expectancy (SLE) is calculated as the value of the asset multiplied by the Exposure Factor (EF). In this case, SLE =12,000. The Annualized Rate of Occurrence (ARO) is 1/5 (since the server crashes once every five years) = 0.2. The Annualized Loss Expectancy (ALE) is calculated as SLE * ARO. In this case, ALE= 12,000 * 0.2= 2,400.