Mod 12: Risk Management Processes

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/40

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

41 Terms

1
New cards

How are dependencies identified between mission essential functions?

BPAs

2
New cards

What do BPAs identify?

Inputs, hardware, staff, outputs, process flow

3
New cards

What is a BIA? What does it do?

Business Impact Analysis helps understand the potential effects of disruptions, helps quantify losses from disruptions

4
New cards

What are MEFs?

Mission Essential Functions are functions that are vital to business operation

5
New cards

What are PBFs?

Primary business functions are important but not as important as MEFs

6
New cards

What 4 metrics should be included in the analysis of MEFs?

MTD, RTO, WRT, RPO

7
New cards

What is MTD?

Maximum Tolerable Downtime is the longest period of time a business function outage can occur before causing irrecoverable failure

8
New cards

What is RTO?

Recovery Time Objective is the period following a disaster that an individual system may be down

9
New cards

What is WRT?

Work Recovery Time is the period following system recovery when additional work or testing is done

10
New cards

What is RPO?

Recovery Point Objective identifies the max acceptable data loss an organization can tolerate in a disaster or failure

11
New cards

What 2 metrics combined should not exceed MTO?

RTO + WRT

12
New cards

What is MTBF? What is equation is used to calculate this?

Mean Time Between Failures represents the average amount of time between failures, total operational time * # of failures

13
New cards

What is MTTR? What equation is used to calculate this?

Mean Time To Repair is the amount of time taken to correct a fault to bring a system to full operation

14
New cards

What are some risk management strategies? (3)

Risk mitigation, risk reduction, risk avoidance

15
New cards

What is risk transference?

Assigning risk to a 3rd party

16
New cards

What is a risk exception?

Risk is recognized but cannot be mitigated in the moment but will be

17
New cards

What is a risk exemption?

Risk is recognized and allowed due to a number of reasons

18
New cards

What is residual risk?

Likelihood of risk after a solution has been applied

19
New cards

What are the 2 main variables in calculating risk?

Likelihood, impact

20
New cards

What are risk assessments?

Identifies risks and their likelihood and impacts

21
New cards

What are the 4 risk assessment methodologies?

Ad hoc, recurring, one time, continuous

22
New cards

What is quantitative risk analysis?

Assigns concrete values to risk factors

23
New cards

What is SLE? How is this calculated?

Single Loss Expectancy is the amount that would be lost in the single occurrence of a risk factor, value of asset * exposure factor

24
New cards

What is ALE? How is this calculated?

Annualized Loss Expectancy is the amount that would be lost over the course of a year, SLE * ARO

25
New cards

What is ARO?

Annualized Rate of Occurrence is the number of times in a year an event occurs

26
New cards

What is qualitative risk analysis?

Assess risks based on subjective judgement rather than precise data

27
New cards

What is inherent risk?

Level of risk before any mitigation has been attempted

28
New cards

What is a risk register?

Results of risk assessments in a comprehensible format

29
New cards

What is a risk threshold?

Limit of acceptable risk an organization can tolerate

30
New cards

What are KRIs?

Key Risk Indicators are predictive indicators used to monitor and predict potential risks

31
New cards

What is a risk owner?

Individual responsible for managing a particular risk

32
New cards

What is a risk appetite?

The level of risk an organization is willing to accept

33
New cards

What is risk tolerance?

Determines the thresholds that separate the different levels of risk

34
New cards

What are the 3 levels of risk appetite?

Expansionary, conservative, neutral

35
New cards

What is a BCP?

Business Continuity Plan is a plan to maintain business operations during reduced or restricted infrastructure and identifies actions required to restore business to normal operation

36
New cards

What is COOP?

Continuity Of Operations he process of ensuring an organization can maintain or quickly resume critical functions in the event of disruption

37
New cards

What is capacity planning?

The assessment of current and future resource requirements needed to meet business objectives

38
New cards

What is due diligence?

Gathering of info about potential vendors

39
New cards

What is RoE?

Rules of engagement define the parameters and expectations for vendor relationships

40
New cards

What are 5 initial agreements between organizations and vendors?

MOU, NDA, MOA, BPA, MSA

41
New cards

What is attestation?

Verifying and validating security controls, systems, and processes