risk management processes and concepts Flashcards

1
Q

A _____ is a repository for documenting risks identified in an organization and includes information and steps to take regarding the risk. Common information found in a _____ is the specific risk, the likelihood of occurrence, and the action to take.

A

risk register

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A _____ assessment evaluates all elements required to produce and distribute a product.

A

supply chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

_____ is the likelihood and impact after specific mitigation, transference, or acceptance measures have been applied.

A

Residual risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

_____ is a measure of how much less effective a security control has become over time.

A

Control risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

_____ is the level of risk before any type of mitigation has been attempted.

A

Inherent risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

_____ is a strategic assessment of what level of residual risk is tolerable and is broad in scope.

A

Risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The _____ identifies a point in time that data loss is acceptable.

A

recovery point objective (RPO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The _____ identifies the maximum time it takes to recover a system in the event of an outage.

A

recovery time objective (RTO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The _____ provides a measure of a system’s average reliability and is measured in hours.

A

mean time between failure (MTBF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The _____ is the average time it takes to restore a system after an outage.

A

mean time to recover (MTTR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly