Security Management Programs and Oversight: Risk Identification and Risk Assessment Flashcards
1
Q
What is the process of Risk Identification?
A
Process of risk identification
Risk identification in a modern organization often includes the following processes:
Threat assessment
Vulnerability analysis
Asset inventory
Impact assessment
Likelihood evaluation – Table top exercise
Risk scenarios
Risk ranking
Mitigation planning
Ongoing monitoring
Documentation
2
Q
What is Risk Assessment criteria?
A
Risk assessments should be performed on a schedule, such as:
On an ad-hoc basis.
On a recurring schedule.
One time only
On a continuous basis.