Font size
WorksheetsChapter 27: Security Risk Management
Total questions: 10
Worksheet time: 20mins
The terms “ threat ” and “ risk ” can be used interchangeably; for example, a “ threat assessment ” is the same as a “ risk assessment. ”
True
False
The concept of “ risk management ” originated within the security profession.
True
False
Because vulnerabilities are actually a characteristic of the organization or facility, they are:
The risk factor over which the organization has the most control
Impossible to accurately assess by an outside consultant
The risk factor that is most expensive to correct
The only risk factor that can be influenced by the organization
According to “ Primer on Security Risk Management, ” the primary categories of threats are (choose all correct answers):
Criminal
Intentional
Inadvertent
Terrorist
Natural
In a scatter chart used for risk analysis, which quadrant represents a “ high-likelihood/ high-consequence ” risk?
Quadrant 1
Quadrant 2
Quadrant 3
Quadrant 4
In order to effectively mitigate risks, a security professional should:
Limit their strategy to using proven security measures only
Assess all possible threats to the organization
Apply a protection strategy that employs a suite of solutions
Ensure that management is aware of existing vulnerabilities
Buying insurance is one example of:
Risk spreading
Risk transfer
Risk avoidance
Risk reduction
Which one of the following is not one of the underlying concepts on which a risk mitigation strategy should be based?
The five avenues to address risk
The “ Four D’s ”
Layered security
Quantitative analysis
Risk management is a critical process that touches every aspect of organizational asset protection — and the activities of the professional protection officer.
True
False
Service providers should not base their core business model on risk management principles.
True
False
