9: Risk Management

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/42

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:12 AM on 8/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

43 Terms

1
New cards

Risk Management

Process of identifying, analyzing, treating, monitoring, and reporting risks to achieve objectives.

2
New cards

5 Steps of Risk Management Lifecycle

  1. Identification
3
New cards
  1. Analysis
4
New cards
  1. Treatment
5
New cards
  1. Monitoring
6
New cards
  1. Reporting
7
New cards

Risk Identification

Proactive process of recognizing potential risks that could disrupt operational objectives.

8
New cards

Risk Analysis

Evaluating the likelihood and potential impact of risks to prioritize them.

9
New cards

Risk Treatment

Developing strategies (avoid, reduce, share, accept) to reduce risk to acceptable levels.

10
New cards

Risk Monitoring

Ongoing tracking of identified risks, residual risks, new risks, and control effectiveness.

11
New cards

Risk Reporting

Communicating risk data and management effectiveness to relevant stakeholders.

12
New cards

Ad-hoc Risk Assessment

Assessment conducted as needed in response to specific events or situational changes.

13
New cards

Recurring Risk Assessment

Assessment conducted at regular, scheduled intervals (e.g., monthly, quarterly, annually).

14
New cards

One-time Risk Assessment

Assessment conducted for a specific project or initiative and not repeated.

15
New cards

Continuous Risk Assessment

Real-time, ongoing evaluation of risks, often enabled by technology and monitoring tools.

16
New cards

Business Impact Analysis (BIA)

Evaluating potential effects of operational disruptions to prioritize recovery of critical functions.

17
New cards

Recovery Time Objective (RTO)

Maximum acceptable duration of downtime before unacceptable consequences occur.

18
New cards

Recovery Point Objective (RPO)

Maximum acceptable amount of data loss measured in time.

19
New cards

Mean Time to Repair (MTTR)

Average time required to repair a failed system or component.

20
New cards

Mean Time Between Failures (MTBF)

Average operational time expected between system or component failures.

21
New cards

Risk Register

Document tracking identified risks, descriptions, impacts, likelihoods, owners, and mitigations.

22
New cards

Risk Appetite

The total amount and type of risk an organization is willing to pursue.

23
New cards

Expansionary Risk Appetite

Willingness to take higher risks for potential higher returns.

24
New cards

Conservative Risk Appetite

Preference for lower risk to prioritize stability and sustainability.

25
New cards

Neutral Risk Appetite

A balanced approach between taking calculated risks and ensuring steady growth.

26
New cards

Risk Tolerance (Acceptance)

The maximum degree of uncertainty or risk an organization is prepared to absorb.

27
New cards

Key Risk Indicator (KRI)

Predictive metric providing early signals of increasing risk exposure.

28
New cards

Risk Owner

Individual or group accountable for monitoring, managing, and mitigating a specific risk.

29
New cards

Qualitative Risk Analysis

Subjective risk evaluation using descriptive rating scales (e.g., Low, Medium, High).

30
New cards

Quantitative Risk Analysis

Objective risk evaluation using numerical data, financial metrics, and statistical probabilities.

31
New cards

Exposure Factor (EF)

Percentage of an asset lost due to a specific risk event (0% to 100%).

32
New cards

Single Loss Expectancy (SLE)

Monetary value lost in a single risk occurrence (SLE = Asset Value × EF).

33
New cards

Annualized Rate of Occurrence (ARO)

Estimated frequency with which a specific threat occurs in one year.

34
New cards

Annualized Loss Expectancy (ALE)

Expected yearly financial loss from a specific risk (ALE = SLE × ARO).

35
New cards

Risk Transference

Shifting financial liability of risk to a third party (e.g., insurance, indemnity clauses).

36
New cards

Indemnity Clause

Contractual agreement where one party agrees to compensate another for harm or loss.

37
New cards

Risk Acceptance

Acknowledging a risk and choosing not to implement controls due to cost or impact.

38
New cards

Risk Exemption

Excluding a party entirely from a rule, absorbing any unmonitored risk.

39
New cards

Risk Exception

Allowing a temporary waiver from a security rule under specific conditions.

40
New cards

Risk Avoidance

Changing plans or stopping activities entirely to eliminate risk exposure.

41
New cards

Risk Mitigation

Implementing controls or measures to reduce likelihood or impact of a risk.

42
New cards

Residual Risk

Remaining risk level after security controls and mitigations are applied.

43
New cards

Control Risk

Risk that an existing security control loses effectiveness over time.