1/37
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Risk Management
Process of identifying, analyzing, treating, monitoring and reporting risks
Risk
Analyzed based on Impact + probability
Risk Assessment Frequency: Ad-Hoc
Assessment that are performed as and when needed.
-As a response to a specific event that has the potential to introduce new risk.
(New product release, Change in regulation)
Risk Assessment Frequency: One-time
Conducted for a specific purpose and are not repeated
(New IT system implemented, Organizational change)
Risk Assessment Frequency: One-time
Conducted for a specific purpose and are not repeated
(New IT system implemented, Organizational change)
Risk Assessment Frequency: Continuous
Ongoing monitoring and evaluation of risk.
Risk Identification Process
Recognizing potential risks and conducting a business impact analysis.
Business Impact Analysis
Evaluating the effects of a potential disruption to an organization’s business functions and processes.
Metrics:
-Recovery Time Objective (RTO)
-Recovery Point Objective (RPO)
-Mean Time to Repair (MTTR)
-Mean Time Between Failures (MTBF)
Business Impact Analysis
Evaluating the effects of a potential disruption to an organization’s business functions and processes.
Metrics:
-Recovery Time Objective (RTO)
-Recovery Point Objective (RPO)
-Mean Time to Repair (MTTR)
-Mean Time Between Failures (MTBF)
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss measured in time.
Mean Time to Repair (MTTR)
The average time need to repair a failed component or system
Mean Time Between Failures (MTBF)
Average time between failures
Risk Register (Risk Log)
A document that has all the identified risks
Including:
Description
Impact
likelihood
Mitigation
Cost $
Risk Tolerance / Acceptance
The maximum amount of risk they are willing to accept
Risk Appetite
Organizations approach to risk taking
Risk Appetite: Expansionary
Is open to taking more risk in hopes of greater returns
Risk Appetite: Conservative
Will not take on a lot of risk, even if it leads to lower returns
Risk Appetite: Neutral
Balance between risk and return
Key Risk Indicators (KRIs)
Predictive Metrics used to signal rising risk levels in different parts of the enterprise. (Early warning system for potential risk)
Risk Owner
Person/Group responsible for managing the risk
Qualitative Risk Analysis
Method of assessing risks based on their potential impact and the likelihood of their occurrence.
Categories (High, Medium, Low)
Impact
Potential damage to an operation if the risk occurs.
Quantitative Risk Analysis
Evaluating risk that uses numerical measurements.
Exposure Factor (EF)
Single Loss Expectancy (SLE)
Annualized Rate of Occurrence (ARO)
Annualized Loss Expectancy (ALE)
Exposure Factor (EF)
Proportion of an asset that is lost in an event
Single Loss Expectancy (SLE)
Monetary value expected to be lost in a single event
(Asset x EF) = SLE
Annualized Rate of Occurrence (ARO)
Estimated frequency with which a threat is expected to occur within a year.
Annualized Loss Expectancy (ALE)
Expected Annual loss from a risk
(SLE x ARO)
Risk Management Strategies
Transfer
Accept
Avoid
Mitigate =
Risk Management: Transfer / Sharing
Involves shifting risk from the organization to another party
(Insurance or Contract Indemnity)
Risk Management: Acceptance
Recognizing a risk and choosing to address it when it happens with any mitigation.
(When cost of prevention > potential loss)
Exemption
A provision that grants an exception from a specific rule or requirement
Exception
Provision that permits a party to bypass a rule in certain situations.
Risk Management: Avoidance
Altering plans to eliminate a risk
(When risk is too great to accept or transfer)
Risk Management: Mitigation
Implementing measures to decrease the likelihood or impact of a risk
Risk Monitoring
Tracking identified risks, assessing new risk, doing response plans and evaluating their effect during a projects lifecycle
Residual Risk
Likelihood and impact after implementing mitigation, transference, acceptance measure of the initial risk
Control Risk
Assessment of how a security measure has lost effectiveness over time
Risk Reporting
Communicating info about risk management actions