1/31
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
acceptance
The risk response where the risk owner accepts risk without providing or dedicating any resources in the effort to protect an asset
access and control policies
Security policies that detail how an organization’s assets can access and make changes to other assets in the organization
asset
An item of value to an institution such as data, hardware, software or physical property
asset inventory
An inventory of assets owned by an organization that details its value and any identified vulnerabilities
asset owner
An individual (or individuals) who has technical or domain-specific knowledge of an asset to provide support and expert recommendations to the risk owner for the appropriate risk response
avoidance
The risk response where the risk owner reduces or eliminates risks by utilizing resources or changing the probability of threats
change management
The policies and procedures for an organization to manage change to minimize the risk that any change can cause
classification
Identifying and labeling different sets of information and how much protection from threats the labeled sets require
communication policies
Policies an organization implements that deal with interactions between the organization and third parties
data portability
Another risk when utilizing the cloud. Data can be difficult or costly to extract from one CSP and import into another CSP
data privacy
Policies implemented by CSPs that govern responsibilities and requirements of keeping data private while it is on their infrastructure
department-specific policies
Policies implemented by an organization that are specific to a department instead of the entire organization as a whole, including security policies and other policies
findings
A document of a risk event, there are four types of finding documents produced: criminal, civil, regulatory, and operational
General Data Protection Regulation (GDPR)
A regulation in the European Union (EU) law on data protection and privacy for all EU residents
incident response
The defined procedure from a security policy once a risk event occurs to an asset or assets
mitigation
A risk response where the risk owner reduces the probability of a threat against an asset by utilizing resources
ownership
The authority to make responsible decisions to an identified risk or for the underlying asset
Payment Card Industry Data Security Standard (PCI DSS)
A compliance requirement for processing or handling credit card transactions
policies
Thoughts, ideas, or principles that give direction for actions to be performed by individuals or organizations as a whole
procedures
A set of steps or actions that should be taken to enact a policy once events occur
qualitative risk assessment
Ranking risks or asset value based on experience, intuition, or a specific scenario
quantitative risk assessment
Assigning a monetary value to the elements of risk or the assets themselves
reporting
Providing an account of observed activity or usage
resource group
A collection of resources that can be grouped or are similar that allows them to be managed as a whole or with broad policies
resource management
The policies and procedures that an organization implements to manage its resources and the risks associated with its assets
risk
The probability or likelihood of the occurrence or realization of a threat
risk owner
A management-level position that will decide and assume the risk response to identified risks
risk register
Documentation of every risk identified by an organization, used by management in formulating appropriate response to risks
risk response
A decision made by the risk owner as being the appropriate level of protection for an asset in response to risk
security policies
A document that defines the scope of security needed by the organization and discusses the assets that require protection
standard operating procedures (SOP)
Procedures that are documented for initiating a change in an organization
threat
Any agent, condition, or circumstance that could potentially cause harm, loss, damage, or compromise to an IT asset or data asset