Section 6: Risk Assessments Flashcards

1
Q

Quantitative

A

Use of numerical values to determine asset values and projected loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Qualitative

A

Use subjective judgment to determine asset values and projected loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Asset Value (AV)

A

How much an asset is worth or costs to repair/replace

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Exposure Factor (EF)

A

Percentage of potential loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Single Loss Expectancy (SLE)

A

Cost of a single loss of an asset
Calculated through AV * EF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Annualized Rate of Occurrence (ARO)

A

Estimated number of a threat occurrence per year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Annualized Loss Expectancy (ALE)

A

Cost of overall loss per year
Calculated through SLE * ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Annual Cost of Safeguard (ACS)

A

Cost of a countermeasure for the asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Cost Benefit Analysis Formula

A

(ALE1 - ALE2) - ACS
ACS - safeguard is $30,000
ALE 1 - $150,000 prior to implementation of safeguard
ALE 2 - $45,000 after implementation of safeguard
ALE 1 - ALE 2 = $105,000
$105,000 - $30,000 = $75,000 total savings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Delphi Technique

A

Anonymous survey process to encourage honest responses to help reach a consensus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Hybrid Analysis

A

Combining quantitative and qualitative results to perform a risk analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Security Control Assessment

A

Evaluate controls required to meet security objectives through system development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Privacy Control Assessment Steps

A

Prepare - identify objective, scope, timeframe, etc
Develop - identify which controls will be tested, get approval
Conduct - assess controls, create report
Analyze - review findings, address gaps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly