Risk Management and Control Flashcards
What is risk?
- Future
- Asset
- Objectives or Goals
What is a cyber-risk?
Risk that is caused by a cyber threat
What is new in the modern viewpoint on risk?
Effect can be positive or negative!
What are the steps in the Risk Management Cycle?
- Establish the context
- Identify the risks
- Analyse the risks
- Evaluate the risks
- Treat the risks
- Communication and consultation
Why risk management may fail?
- Limitations of scope
- Lack of top management support
- Did not engage all stakeholders
- Failure to share information
- Risk management not embedded within planning & management
What are the three components of the ISO 31000 for Risk Management?
- Principles
- Framework
- Process
What is the extra step in the risk management process compared with the Risk Management Cycle?
- Monitoring and review
What are the steps in the Risk Management Framework?
- Design of management framework
- Implement Risk Management
- Monitoring & Review
- Continual Improvement
- Mandate
How do the Risk Management Framework, Risk Management Process and Risk Management Principles fit together?
Principles + Framework = Process
What is the difference between classical access control and RBAC?
In RBAC, the access to objects is based on the user’s role, while in classical access control access is based on the user itself
What steps do we take in a cybersecurity risk assessment?
- Characterise the system
- Identify the threats
- Determine inherent risk and impact
- Analyse the control environment
- Determine a likelihood rating
- Risk assessment matrix