CISSP · CISSP

CISSP Domain 1: Security and Risk Management

Risk management frameworks, security governance, and compliance concepts tested on the CISSP exam's first domain.

41 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Get FlashKeepers for iPhone
What is risk in information security?
The probability that a threat will exploit a vulnerability, resulting in a loss or impact to an asset
Define an asset in the context of security.
Anything of value to an organization that needs to be protected, including people, data, systems, and infrastructure
What is a threat?
Any potential cause or source of harm that may exploit a vulnerability and cause damage or loss
What is a vulnerability?
A weakness in a system, process, or control that can be exploited by a threat
Express the risk formula.
Risk = Threat x Vulnerability x Asset Value, or Risk = Probability of Threat x Impact
What is qualitative risk assessment?
A risk assessment method using subjective judgments and scales such as high, medium, low instead of numerical values
What is quantitative risk assessment?
A risk assessment method using numerical values and mathematical calculations to determine risk levels and expected losses
Define Annualized Loss Expectancy (ALE).
The expected monetary loss per year, calculated as SLE multiplied by ARO
Define Single Loss Expectancy (SLE).
The expected monetary loss from a single occurrence of a threat, calculated as Asset Value multiplied by Exposure Factor
Define Annualized Rate of Occurrence (ARO).
The estimated number of times a threat is expected to occur within one year
What are the four primary risk response strategies?
Risk mitigation, risk avoidance, risk acceptance, and risk transfer
Define risk acceptance.
Choosing to accept the consequences and costs of a risk materializing rather than taking action to prevent it
Define risk mitigation.
Implementing controls or measures to reduce the likelihood or impact of a risk to an acceptable level
Define risk avoidance.
Eliminating the activity, asset, or exposure that creates the risk entirely
Define risk transfer.
Moving or sharing the financial impact of a risk to a third party, typically through insurance or outsourcing

26 more cards in the app