Risk Mgmt Flashcards
data classification mechanism objective
cost reduction more than security
data purging responsibility
data owner.. more functional role than security
COBIT provides
Control objectives Control Practices Goal indicators Performance indicators success factors Maturity Models
Delayed loss risk
Employee Productivity
Qualitative risk analysis
Threat modeling
Standards
Rules on how to accomplish policy objectives
Risk Analysis is related to
uncertainty analysis.
BC & DR provides
compensating control
Policy developement Lifecycle
initiation, evaluation, development, approval, publication, implementation, maintenance
If data is going to be used by more people
it should be more securely controlled.
To classify the data, data owner should evaluate
CIA requirements
effective security program needs balanced
technical and non technical methods
Truly quantitative risk analysis is not possible because
quantitative measures must be applied to qualitative elements
technical focused policies
system specific
key for any project such as risk analysis
project sizing, scope