risk management processes and concepts Flashcards
A _____ is a repository for documenting risks identified in an organization and includes information and steps to take regarding the risk. Common information found in a _____ is the specific risk, the likelihood of occurrence, and the action to take.
risk register
A _____ assessment evaluates all elements required to produce and distribute a product.
supply chain
_____ is the likelihood and impact after specific mitigation, transference, or acceptance measures have been applied.
Residual risk
_____ is a measure of how much less effective a security control has become over time.
Control risk
_____ is the level of risk before any type of mitigation has been attempted.
Inherent risk
_____ is a strategic assessment of what level of residual risk is tolerable and is broad in scope.
Risk appetite
The _____ identifies a point in time that data loss is acceptable.
recovery point objective (RPO)
The _____ identifies the maximum time it takes to recover a system in the event of an outage.
recovery time objective (RTO)
The _____ provides a measure of a system’s average reliability and is measured in hours.
mean time between failure (MTBF)
The _____ is the average time it takes to restore a system after an outage.
mean time to recover (MTTR)