Risk Types Flashcards

1
Q

General vs. Specialized Risk Management

A

General risk management applies to broad contexts, while specialized risk management targets specific domains.

Example: General: ISO31000 for overall risk frameworks. Specialized: ISO/IEC27005 for information security risk management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Organization-Centric Risk Management

A

Focuses on risks affecting the organization as a whole, often conflicting with other entities’ risks.

Example: A company avoids costly code quality measures to reduce financial risk, impacting a client who must implement compensating controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SE Project-Centric Risk Management

A

Centers on risks specific to software projects, including misaligned organizational and project goals.

Example: A project accepts coding shortcuts to meet deadlines but faces post-release security vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Application-Centric Risk Management

A

Focuses on technical risks tied to software applications, including coding, testing, and environmental security.

Example: An application runs on unpatched operating systems, increasing vulnerability to attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Supply Chain Risk Management

A

Manages risks tied to subcontractors and third-party dependencies.

Example: Choosing a subcontractor in a risky jurisdiction without confidentiality clauses in the contract.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk Management in Emerging Technologies

A

Handles risks from technologies with rapid growth, novelty, and uncertainty.

Example: Quantum computing introduces uncertainty in cryptographic algorithms and adoption impacts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Risk Management through IT Auditing and Checklists

A

Uses control-based or risk-based audits to identify and manage risks systematically.

Example: A risk-based audit identifies gaps in cloud service provider controls and suggests mitigation steps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Business Continuity Management as a Risk Management Tool

A

Prepares for operational resilience and disaster recovery in IT systems.

Example: Using cloud backups to meet a client’s RPO (maximum acceptable data loss) of 1 hour.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List of all types of risk perspectives

A
  • General vis-a-vis specialized risk management
  • Organization-centric risk management
  • SE Project Centric risk management
  • Application-centric risk management
  • Supply chain risk management
  • Risk management in emerging technologies
  • Risk management through IT auditing and checklists.
  • Business continuity management as a risk management tool.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly