Risks Management Flashcards
Security Policy Framework Levels
Policies
Standards
Guidelines
Procedures
Risk Factors
Likelihood/probability
Impact
Risk Assessment Methods
Qualitative
Quantitative
Define an AV
Asset Value
AV Assessment Methods
Original
Depreciated
Replacement
Define the EF
Exposure Factor; percent of asset effected
Define SLE
Single Loss Expectancy; AV * EF
Define ARO
Annualized Rate of Occurrence; likely number of occurrences per a year
Define ALE
Annualized Loss Expectancy; ALE = SLE * ARO
Define MTTF
Mean Time to Failure, for non replaceable components
Define MTBF
Mean Time Between Failures, for replaceable components
Define MTTR
Mean Time To Repair, average restoration time
Risks Response Types
Avoidance
Transference
Mitigation/Deterrence
Acceptance
Risk Register Components
Description Categorization Probability Impact Mitigation
Risk Assessment Sources
Vulnerability Scans Penetration Test Audits OS Threat Intelligence Consulting/Vendor
Types of Vendor Agreements
SLR/SLA
MOU/MOA
BPA/BPO
ISA
Define SLR
Service-Level Agreement; outlines service providers commitment to client
Define MOU/MOA
Memorandum of Understanding/Agreement
Define BPA
Business Partnership Agreement
Define ISA
Interconnection Service Agreement; joins networks outlining technical and security requirements
Personnel Risk Management Key Principles
Need to Know
Least Privilege
Separation of Duties
Define a BCP
Business Continuity Planning; focus on maintaining availability
Define a BIA
Business Impact Assessment
BIA Risk Concerns
Safety
Financial
Reputation
Define High Availability
Multiple-systems for same purpose
Fault Tolerance Methods
Power Supply
Memory Storage
Describe RAID O
Striping
Performance, no Redundancy
1 or more disks
Describe RAID 1
Mirroring
Redundancy, low performance
2 or more disks
Describe RAID 5
Striping with Parity
Performance and Redundancy
3 or more disks
Describe RAID 6
Striping with Double Parity
4 or more disks
Describe RAID 10 (also called RAID 1 + 0/0 + 1)
Striping and Mirroring
4 or more disks
Define RTO
Recover Time Objective, goal recovery time
Define RPO
Recovery Point Objective, restoration point to return to after an incident