1/9
Vocabulary flashcards for key concepts covered in the Advanced Information Security lecture on Risk Management.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Mission Statement
A statement of an organization's ongoing purpose and reason for existence.
Objectives
Statements of activities or end-states that the organization wishes to achieve, supporting the organization’s mission.
Goals
Specific accomplishments that will enable the organization to meet its objectives.
Risk Management
The process of determining the maximum acceptable level of overall risk to and from a proposed activity.
Qualitative Risk Assessment
The process of identifying vulnerabilities, threats, threat probability, and impact for a given scope of assets.
Quantitative Risk Assessment
An extension of a qualitative risk assessment that involves determining expected losses from potential attacks.
Countermeasures
Strategies implemented to reduce risk or mitigate impacts of identified threats.
Risk Treatment
The action taken to address identified risks, which may include acceptance, avoidance, reduction, or transfer of risk.
Residual Risk
The remaining risk after risk treatment has been applied.
NIST 800-30
A risk management guide for information technology systems.