1/28
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
enterprise risk management(ERM)
the comprehensive process of evaluating, measuring, and mitigating the many risks that pervade an organization
risk identification process
frame - establish a strategic risk management framework that is supported by decision makers at the top tier of the organization
assess - identify and prioritize business processes and workflows
respond- mitigate each risk factor through the deployment of managerial, operational, and technical security controls
monitor- evaluate the effectiveness of risk response measures and identify changes that could affect risk management processes
business continuity loss
a loss associated with no longer being able to fulfill contracts and orders due to the breakdown of critical systems
legal costs
a loss created by organizational liability due to prosecution (criminal law) or damages(civil law)
reputational harm
a loss created by negative publicity and the consequential loss of market position or consumer trust
system assessments
the systematic identification of critical systems by compiling an inventory of the business processes and the tangible and tangible assets and resources that support those processes
mission essential function(MEF)
a business or organizational activity too critical to be deferred for anything more than a few hours
asset/inventory tracking
the use of a software or hardware solution to track and manage any assets within an organization
threat and vulnerability assessment
an ongoing process of assessing assets against a set of known threats and vulnerabilities
quantitative method
uses mathematical and statistical techniques to assign numerical values to the likelihood and impact of potential threats
risk = probablity x impact
50% or 90%
0.5 or 0.9
single loss expectancy(SLE)
a metric to determine the expected financial loss from a single event
SLE = AV(asset value) x EF(exposure factor)
asset value
monetary value of the asset that is at risk
exposure factor(EF)
percentage of loss that would result from a specific threat
annual rate of occurence(ARO)
number of times per year that a specific threat is expected to occur
ARO = # of threat occurence divided by # of years in the period
annual loss expectancy(ALE)
expected financial loss for multiple events during a year
ALE = single loss expectency(SLE) x annual rate of occurence(ARO)
qualitative method
uses subjective judgement and expert opinions to evaluate the likelihood and impact of threats
business impact analysis(BIA)
a systematic activity that identifies organizational risks and determines their effect on ongoing mission critical operations
maximum tolerable downtime(MTD)
the longest period of time a business can be inoperable without causing irrevocable business failure
recovery time objective(RTO)
the length of time it takes after an event to resume normal business operations and activities
work recovery time(WRT)
the length of time in addition to the RTO of individual systems to perform reintegration and testing of a restored or upgraded system following an event
recovery point objective(RPO)
the longest period of time that an organization can tolerate lost data being unrecoverable
focused on how long you can be without your data
return on security investment(ROSI)
metric to calculate whether a security control is worth the cost of deploying and maintaining it
engineering tradeoff
assessment of the benefit of risk reduction against the increased complexity or cost in a system design or specification
risk register
document highlighting the results of risk assessments in an easily comprehensible format
compensating control
type of security control that acts as a substitute for a principal control
exception management
formal process that is used to document each case where a function or asset is noncompliant with written policy and procedural controls
red team
hostile or attacking team in a penetration test or incident response exercise
blue team
defensive team in penetration test or indicent response exercise
white team
staff administering, evaluating and supervising a penetration test or incident response exercise