Risk management frameworks, security governance, and compliance concepts tested on the CISSP exam's first domain.
41 cards · basic cards · AI-written, checked twice. Edit anything.
- What is risk in information security?
- The probability that a threat will exploit a vulnerability, resulting in a loss or impact to an asset
- Define an asset in the context of security.
- Anything of value to an organization that needs to be protected, including people, data, systems, and infrastructure
- What is a threat?
- Any potential cause or source of harm that may exploit a vulnerability and cause damage or loss
- What is a vulnerability?
- A weakness in a system, process, or control that can be exploited by a threat
- Express the risk formula.
- Risk = Threat x Vulnerability x Asset Value, or Risk = Probability of Threat x Impact
- What is qualitative risk assessment?
- A risk assessment method using subjective judgments and scales such as high, medium, low instead of numerical values
- What is quantitative risk assessment?
- A risk assessment method using numerical values and mathematical calculations to determine risk levels and expected losses
- Define Annualized Loss Expectancy (ALE).
- The expected monetary loss per year, calculated as SLE multiplied by ARO
- Define Single Loss Expectancy (SLE).
- The expected monetary loss from a single occurrence of a threat, calculated as Asset Value multiplied by Exposure Factor
- Define Annualized Rate of Occurrence (ARO).
- The estimated number of times a threat is expected to occur within one year
- What are the four primary risk response strategies?
- Risk mitigation, risk avoidance, risk acceptance, and risk transfer
- Define risk acceptance.
- Choosing to accept the consequences and costs of a risk materializing rather than taking action to prevent it
- Define risk mitigation.
- Implementing controls or measures to reduce the likelihood or impact of a risk to an acceptable level
- Define risk avoidance.
- Eliminating the activity, asset, or exposure that creates the risk entirely
- Define risk transfer.
- Moving or sharing the financial impact of a risk to a third party, typically through insurance or outsourcing