1/42
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Risk Management
Process of identifying, analyzing, treating, monitoring, and reporting risks to achieve objectives.
5 Steps of Risk Management Lifecycle
Risk Identification
Proactive process of recognizing potential risks that could disrupt operational objectives.
Risk Analysis
Evaluating the likelihood and potential impact of risks to prioritize them.
Risk Treatment
Developing strategies (avoid, reduce, share, accept) to reduce risk to acceptable levels.
Risk Monitoring
Ongoing tracking of identified risks, residual risks, new risks, and control effectiveness.
Risk Reporting
Communicating risk data and management effectiveness to relevant stakeholders.
Ad-hoc Risk Assessment
Assessment conducted as needed in response to specific events or situational changes.
Recurring Risk Assessment
Assessment conducted at regular, scheduled intervals (e.g., monthly, quarterly, annually).
One-time Risk Assessment
Assessment conducted for a specific project or initiative and not repeated.
Continuous Risk Assessment
Real-time, ongoing evaluation of risks, often enabled by technology and monitoring tools.
Business Impact Analysis (BIA)
Evaluating potential effects of operational disruptions to prioritize recovery of critical functions.
Recovery Time Objective (RTO)
Maximum acceptable duration of downtime before unacceptable consequences occur.
Recovery Point Objective (RPO)
Maximum acceptable amount of data loss measured in time.
Mean Time to Repair (MTTR)
Average time required to repair a failed system or component.
Mean Time Between Failures (MTBF)
Average operational time expected between system or component failures.
Risk Register
Document tracking identified risks, descriptions, impacts, likelihoods, owners, and mitigations.
Risk Appetite
The total amount and type of risk an organization is willing to pursue.
Expansionary Risk Appetite
Willingness to take higher risks for potential higher returns.
Conservative Risk Appetite
Preference for lower risk to prioritize stability and sustainability.
Neutral Risk Appetite
A balanced approach between taking calculated risks and ensuring steady growth.
Risk Tolerance (Acceptance)
The maximum degree of uncertainty or risk an organization is prepared to absorb.
Key Risk Indicator (KRI)
Predictive metric providing early signals of increasing risk exposure.
Risk Owner
Individual or group accountable for monitoring, managing, and mitigating a specific risk.
Qualitative Risk Analysis
Subjective risk evaluation using descriptive rating scales (e.g., Low, Medium, High).
Quantitative Risk Analysis
Objective risk evaluation using numerical data, financial metrics, and statistical probabilities.
Exposure Factor (EF)
Percentage of an asset lost due to a specific risk event (0% to 100%).
Single Loss Expectancy (SLE)
Monetary value lost in a single risk occurrence (SLE = Asset Value × EF).
Annualized Rate of Occurrence (ARO)
Estimated frequency with which a specific threat occurs in one year.
Annualized Loss Expectancy (ALE)
Expected yearly financial loss from a specific risk (ALE = SLE × ARO).
Risk Transference
Shifting financial liability of risk to a third party (e.g., insurance, indemnity clauses).
Indemnity Clause
Contractual agreement where one party agrees to compensate another for harm or loss.
Risk Acceptance
Acknowledging a risk and choosing not to implement controls due to cost or impact.
Risk Exemption
Excluding a party entirely from a rule, absorbing any unmonitored risk.
Risk Exception
Allowing a temporary waiver from a security rule under specific conditions.
Risk Avoidance
Changing plans or stopping activities entirely to eliminate risk exposure.
Risk Mitigation
Implementing controls or measures to reduce likelihood or impact of a risk.
Residual Risk
Remaining risk level after security controls and mitigations are applied.
Control Risk
Risk that an existing security control loses effectiveness over time.