1/27
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a risk assessment?
The process of identifying risks, evaluating their likelihood and impact, and prioritizing them so resources go to what matters most.
What are the types of risk assessment by frequency?
Ad hoc — triggered by a specific event.
Recurring — on a set schedule.
One-time — for a specific project or decision.
Continuous — ongoing automated monitoring of risk posture.
What is risk identification?
Systematically finding and documenting what could go wrong, through asset inventory, threat modeling, audits, vulnerability scans, and staff input.
What is qualitative risk analysis?
Rating risk on descriptive scales — high/medium/low or a likelihood-vs-impact matrix. Fast and intuitive, but subjective and hard to compare precisely.
What is quantitative risk analysis?
Assigning monetary values to risk using calculated figures like SLE, ARO, and ALE. Objective and useful for cost justification, but data-intensive.
What is asset value (AV)?
The total monetary worth of an asset — replacement cost, revenue it generates, and the cost of its loss.
What is exposure factor (EF)?
The percentage of an asset's value lost in a single incident, expressed as a decimal. Losing half an asset is an EF of 0.5.
What is single loss expectancy (SLE)?
The expected cost of one occurrence of a risk. SLE = AV × EF.
What is annualized rate of occurrence (ARO)?
How many times a risk is expected to occur in one year. Once every four years is an ARO of 0.25.
What is annualized loss expectancy (ALE)?
The expected annual cost of a risk. ALE = SLE × ARO. Compared against the cost of a control to justify spending.
What is the difference between probability, likelihood, and impact?
Probability is the statistical chance of occurrence.
Likelihood is a qualitative estimate of it.
Impact is the magnitude of harm if it happens.
What is a risk register?
The central document tracking all identified risks — description, owner, likelihood, impact, score, treatment strategy, and current status.
What is a key risk indicator (KRI)?
A metric that signals rising risk exposure before it becomes an incident — such as growing unpatched systems or repeated failed access reviews.
What is a risk owner?
The named individual accountable for managing a specific risk and its treatment. Without one, risks sit unaddressed in the register.
What is risk appetite?
The amount and type of risk an organization is willing to accept in pursuit of its objectives. Typically expressed as expansionary, conservative, or neutral.
What is risk tolerance?
The acceptable variation from risk appetite for a specific risk or system — the threshold above which action is required.
What is a risk threshold?
The defined level at which a risk must be escalated, treated, or formally accepted rather than monitored.
What is inherent risk?
The level of risk before any controls are applied.
What is residual risk?
The risk remaining after controls are applied. It must be formally accepted by management, since no control eliminates risk entirely.
What is control risk?
The risk that a control fails to work as intended or doesn't sufficiently reduce the risk it was chosen to address.
What is risk mitigation?
Applying controls to reduce a risk's likelihood or impact to an acceptable level. The most common strategy.
What is risk transference?
Shifting the financial burden of a risk to a third party through insurance or contractual terms. The responsibility for the outcome remains with you.
What is risk acceptance?
Acknowledging a risk and choosing to take no further action because it falls within tolerance or treatment costs more than the exposure. Must be documented and approved.
What is an exemption vs. an exception in risk acceptance?
An exemption is a permanent, approved release from a requirement. An exception is a temporary, time-bound deviation with a defined review or expiration date.
What is risk avoidance?
Eliminating the risk by not engaging in the activity at all — discontinuing a service, declining a project, or removing the system.
What is a business impact analysis (BIA)?
Identifies critical business functions and quantifies the operational and financial impact of their disruption over time, driving continuity and recovery priorities.
What are RTO and RPO?
Recovery time objective — the maximum acceptable time to restore a function after an outage. Recovery point objective — the maximum acceptable amount of data loss, measured backward in time.
What are MTTR and MTBF?
Mean time to repair — the average time to restore a failed system. Mean time between failures — the average operational time between failures, a measure of reliability.