Risk Reporting Flashcards

1
Q

Capacity for loss

A

Objective measure of how much loss the organization can withstand and remain solvent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Tolerance for Loss

A

Subjective measure of how much loss an organization is willing to withstand.

Tolerance can vary among stakeholders/scenarios.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fragile condition

A

Facing many threat events, but none are becoming loss events because of a single control.

What happens if it fails?

Threat events become loss events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Unstable condition

A

High vulnerability but no threat events. (No threat events at the moment and no controls)

What if threat community starts attacking?

Threat events become loss events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

H/M/L Labels

A

High Medium Low

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Translation table

A

Always required when using H/M/L labels to avoid subjective interpretations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Risk Rating: SV

A

Severe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk rating: H

A

High

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Risk rating: Sg

A

Significant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk rating: M

A

Moderate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk rating: L

A

Low

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk rating: VL

A

Very low

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How to remediate fragile condition…

A

Add additional layers of control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly