Information risk identification, assessment, and treatment concepts tested on the CISM exam.
35 cards · basic cards · AI-written, checked twice. Edit anything.
- What is risk identification in information security?
- The process of discovering, recognizing, and documenting potential security risks and threats to an organization's information assets.
- Name three primary sources of information security risk.
- Threats, vulnerabilities, and asset value.
- What is the purpose of risk assessment?
- To systematically identify, analyze, and evaluate risks to determine their potential impact and likelihood.
- Define risk analysis.
- The process of examining identified risks in detail to understand their nature, probability, and potential consequences.
- What is qualitative risk analysis?
- A method that rates risks using descriptive categories such as high, medium, and low rather than numerical values.
- What is quantitative risk analysis?
- A method that assigns numerical values to risks using data-driven calculations and financial metrics.
- Define risk treatment.
- The process of selecting and implementing strategies to respond to identified risks.
- What is risk mitigation?
- A risk response strategy that reduces the likelihood or impact of a risk through preventive controls or countermeasures.
- What is risk acceptance?
- A risk response strategy in which an organization decides to tolerate a risk and its potential impact.
- What is risk avoidance?
- A risk response strategy where an organization eliminates the activity or asset that creates the risk.
- What is risk transfer?
- A risk response strategy where the cost or responsibility for the risk is passed to a third party, such as through insurance.
- Define risk tolerance.
- The amount of risk an organization is willing to accept in pursuit of its business objectives.
- What is asset valuation?
- The process of determining the economic or operational value of an information asset for risk assessment purposes.
- What is a threat assessment?
- The process of identifying, analyzing, and evaluating potential threats that could exploit vulnerabilities in an organization's assets.
- What is a vulnerability assessment?
- The systematic process of identifying, quantifying, and prioritizing vulnerabilities in systems and applications.