IS372-Chapter5

0.0(0)
studied byStudied by 1 person
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

18 Terms

1
New cards

What is a risk assessment for

A risk assessment also known as a risk analysis is a process used to identify risks

2
New cards

What is a safeguard

A safeguard or control is used to control or reduce the risk it may reduce the impact from a threat or reduce a vulnerability 

3
New cards

What are the 3 critical steps that must be completed early in the risk assessment process

Identify Scope, Critical areas, and team members

4
New cards

What is the difference between a qualitative and quantitative risk assessment

Quantitative is objective meaning it uses hard numbers such as dollar values and requires a large amount of data, Qualitative is subjective meaning it uses values based on opinions from experts 

5
New cards

What is ALE

Annual loss expectancy

6
New cards

What is ARO

Annual rate of occurrence

7
New cards

What is EF 

Exposure Factor describes the percentage of loss an asset would suffer if a specific threat materializes 

8
New cards

Are risk assessments static processes

No they are dynamic and should be frequently revisited

9
New cards

A ____ risk assessment uses SLE

Quantitative

10
New cards

Is a qualitative or quantitative faster to complete 

Qualitative is much faster to complete 

11
New cards

Would qualitative or quantitative include details for a CBA

Quantitative

12
New cards

When completing a risk assessment what can be used to indicate the reliability of the data

Uncertainty level

13
New cards

_______ uses hard numbers and terms like SLE, ARO, CBA while ______ uses stuff like probability and impact

Quantitative, Qualitative 

14
New cards

What is the Risk level formula

Risk level = Probability x Impact

15
New cards

Of the 2 risk assessments which one is more precise

Quantitative

16
New cards

Of the two risk assessment types which one uses terms like high, low, medium

Qualitative

17
New cards

What is the general purpose of a qualitative assessment 

Prioritize and categorize risks 

18
New cards

What is the general purpose of a quantitative assessment 

Measure and calculate risk in financial terms

Explore top flashcards