click below
click below
Normal Size Small Size show me how
Risk management
Risk security program management oversight
| Question | Answer |
|---|---|
| Ad hoc risk assessments | Conducted as and when needed, often in response to a specific event or situation that has the potential to introduce new risks or change the nature of existing risks. Specific events or situations and may be repeated. |
| Recurring risk assessments | Conducted at regular intervals, such as annually, quarterly, or monthly |
| One time risk assessments | Conducted for a specific purpose and are not repeated. Specific project or initiative and are not repeated. |
| Continuous risk assessments | Ongoing monitoring and evaluation of risks |
| Risk identification | Recognizing potential risks that could negatively impact the organization's ability to operate or achieve its objectives |
| Business Impact analysis | Process that involves evaluating the potential effects of disruption to an organizations business functions and processes |
| Recovery time objective (RTO) | It represents the maximum acceptable length of time that can elapse before the lack of a business function, severely impact the organization |
| Recovery point objective (RPO) | Represents the maximum acceptable amount of data loss measured in time |
| Mean time to repair (MTTR) | It represents the average time required to repair a failed component or system |
| Mean time between failures (MTBF) | It represents the average time between failures |
| Risk management | Crucial for projects and businesses, involving the identification and assessment of uncertainties that may impact objectives |
| Risk register (risk log) | A document detailing identified risk, including the description, impact likelihood, and mitigation strategies |
| Risk description | Entails identifying and providing a detailed description of the risk |
| Risk impact | Potential consequences if the risk materializes |
| Risk likelihood/probability | Chance of a particular risk occurring |
| Risk outcome | Result of a risk, linked to its impact and likelihood |
| Risk level/threshold | Determined by combining the impact and likelihood |
| Cost | Pertains to its financial impact on the project, including potential expenses, if it occurs or the cost of risk mitigation |
| Risk tolerance/risk acceptance | Refers to an organization or individuals willingness to deal with uncertainty in pursuit of their goals |
| Risk appetite | Signifies an organizations willingness to embrace or retain specific types and levels of risk to fulfill a strategic goals |
| Expansionary risk appetite | Organization is open to taking more risk in the hopes of achieving greater returns |
| Conservative Risk appetite | Implies that an organization favors less risk, even if it leads to lower returns |
| Neutral risk appetite | Signifies a balance between risk and return |
| Key risk indicators (KRIs) | Essential predictive metrics used by organizations to signal rising risk levels in different parts of the enterprise |
| Risk owner | Person or group responsible for managing the risk |
| Qualitative risk analysis | A method of assessing risk based on their potential impact in the likelihood of their occurrence |
| Quantitative risk analysis | Objective and numerical evaluation of risks. Method of evaluating risk that uses numerical measurements. |
| Exposure factor (EF) | Proportion of an asset that is lost in an event |
| Single loss expectancy (SLE) | Monetary value expected to be lost in a single event |
| Annualized rate of occurrence (ARO) | Estimated frequency with which a threat is expected to occur within a year |
| Annualized loss expectancy (ALE) | Expected an annual loss from a risk (SLE x ARO) |
| Risk Transference (risk sharing) | Involves shifting the risk from the organization to another party |
| Contract indemnity clause | A contractual agreement where one party agrees to cover the others harm liability or loss stemming from the contract |
| Risk acceptance | Recognizing a risk and choosing to address it when it arises |
| Exemption | Provision that grants an exception from a specific rule or requirement |
| Exception | Provision that permits a party to bypass a rule or requirement in certain circumstances |
| Risk avoidance | Strategy of altering plans or approaches to completely eliminate a specific risk. Entails taking actions to entirely steer clear of a particular risk. |
| Risk mitigation | Implementing measures to decrease the likelihood or impact of a risk. Taking steps to reduce the potential impact or likelihood of a risk. Recognize when a risk is escalating mitigate it before becoming an issue |
| Risk transference | Transferring the risk of a loss from one party to another |
| Risk acceptance | Recognizing and embracing a risk without implementing measures to reduce or avoid it |
| Risk monitoring | Involves continuously tracking identified risk, assessing new risks, executing response plans, and evaluating their effectiveness during a project lifecycle |
| Residual risk | Likelihood and impact after implementing mitigation, transparence or acceptance measures on the initial risk |
| Control risk | Assessment of how a security measure has lost effectiveness overtime |
| Risk reporting | Process of communicating information about risk management activities |
| Informed decision-making | Offer insights for informed decisions on resource allocation, project timelines, and strategic planning |
| Stakeholder communication | Assist in setting expectations and showing effective risk management |
| Regulatory compliance | Demonstrate compliance with these regulations |