Risk Management Frameworks Flashcards

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/9

flashcard set

Earn XP

Description and Tags

Question and answer style flashcards covering key aspects of various risk management frameworks, including NIST RMF, NIST CSF, ISO/IEC 27005, COBIT, and FAIR.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

10 Terms

1
New cards

What are the 7 steps of the NIST RMF?

Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.

2
New cards

What are the 5 core functions of the NIST CSF?

Identify, Protect, Detect, Respond, Recover.

3
New cards

Which framework uses financial modeling to quantify risk?

FAIR (Factor Analysis of Information Risk).

4
New cards

Which framework is part of the ISO 27000 series?

ISO/IEC 27005.

5
New cards

What is the main use case for COBIT?

IT governance and aligning security with business objectives.

6
New cards

Which risk management framework is used by the U.S. government and contractors?

NIST RMF (Risk Management Framework)

7
New cards

Which risk management framework is used broadly in the private sector and critical infrastructure and is non-technical friendly?

NIST CSF (Cybersecurity Framework)

8
New cards

Which framework focuses on risk assessment, treatment, monitoring, and ISMS integration (ISO 27001)?

ISO/IEC 27005

9
New cards

Which framework is used for IT governance, performance measurement, and risk optimization?

COBIT (Control Objectives for Information and Related Technologies)

10
New cards

Which risk analysis framework uses financial modeling, focusing on financial impact and probabilistic risk calculation, and measures risk in dollars?

FAIR (Factor Analysis of Information Risk)