Font size
WorksheetsLesson 5.1 InfoSec Risk Management Basics
Total questions: 28
Worksheet time: 21mins
What is Information Security Risk Management?
The forecasting and evaluation of financial risks together with the identification of procedures to avoid or minimize their impact.
It allows the organization to assess, identify, and modify its overall security posture.
It enables security, operations, organizational leadership, and other personnel to collaborate and view the entire organization from an attacker's perspective.
Both B and C
Controlling the likelihood and impact of bad things involving information.
What is a "threat"?
An unpatched system.
A person or thing likely to cause damage or danger.
A virus on a device.
A weakness that results in unwanted attacks.
Both A and B
What type of incident is a misconfiguration?
A threat
A vulnerability
An exploit
Both B and C
What is type of incident is phishing?
A threat
A vulnerability
An exploit
A recreational activity
What is a vulnerability?
The quality of being vulnerable.
The quality of state of being exposed to the possibility of being attacked or harmed, physically or emotionally
A weakness or gap in control.
All of the above.
Explain Risk.
True or false. If there isn't a vulnerability, there isn't a risk.
True
False
Explain why risk is relative.
According to NIST Risk Management Framework, how many steps are in the process?
4
5
6
7
What are the steps involved in the NIST Risk Management Framework?
1. Identify Risk
2. Assess Risk
3. Control Risk
4. Review Controls
1. Identify Risks
2. Measure Risks
3. Examine Solutions
4. Implement Solution
5. Monitor Results
1. Categorize Info Systems
2. Select Security Controls
3. Implement Security Controls
4. Assess Security Controls
5. Authorize Info Systems
6. Monitor Security Controls
1. Identify
2. Analyze
3. Evaluate
4. Prioritize
5. Treat
6. Monitor
If you could simplify the Risk Management Process, which three steps would be critical to include in the cycle?
1. Assess
2. Decide
3. Implement
1. Identify
2. Fix
3. Monitor
1. Guess
2. Solve
3. Pray
1. Assess
2. Fix
3. Monitor
What types of risk assessments are there? Select all that apply.
qualitative
intuitive
quantitative
objective
Is a qualitative risk assessment objective or subjective in nature?
objective
subjective
Both
Neither
Which type of risk assessment requires more expertise but considered less credible?
Qualitative
Intuitive
Quantitative
Objective
What type of risk assessment provides better comparison data, less subjectivity, and more definitive decision-making?
Qualitative
Intuitive
Quantitative
Objective
What type of data is qualitative? Select all that apply
Gender
Income
Social Class
Marital Status
Family size
What type of data is quantitative? Select all that apply
Percent of lecture attended
Type of instruction
Clinical Skills performed
Method of treatment
Number of errors
Why is it important to identify the scope of the risk assessment?
Makes sure you relate to the broadness of the assessment.
Makes sure you account for all the controls.
It is critical to putting risk into context.
All of the above.
What are the 3 controls needed in scope to make sure the enterprise has a comprehensive risk assessment?
administrative, physical and external vulnerabilities
internal, external, and physical threats/ vulnerabilities
Executive, managerial, and information security areas
administrative, physical, and technical threats/ vulnerabilities
When choosing a risk assessment, what are the attributes to look for that make it a better option? Choose all that apply.
Measureability
Context
Comparison
Simplicity
Objectivity
Identify the three things that make measurability valid.
Context
Objectivity
Clarity
Relevance
Objectivity
Consistency
Relevance
Subjectivity
Context
Relevance
Objectivity
Context
A risk without a decision is which risk decision?
Mitigate
Ignore
Accept
Avoid
Transfer
Which of this is not a viable risk decision?
Mitigate
Ignore
Accept
Transfer
Avoid
This risk is not acceptable to the organization and the decision is to share some or all the risk with someone else - usually a 3rd party.
Mitigate
Accept
Ignore
Transfer
Avoid
This risk is not acceptable to the organization and the decision is to stop doing whatever it is/was that led to the risk.
Accept
Avoid
Ignore
Transfer
Mitigate
This risk is acceptable to the organization as-is. There is no need for further action (just because a risk esixts does not mean we have to do something about it.)
Accept
Mitigate
Ignore
Transfer
Avoid
This risk is not acceptable to the organization as-is and must be reduced by reducing the vulnerability or reducing the threat.
Accept
Mitigate
Avoid
Ignore
Transfer
True or False. First decide which risks are acceptable and which are not, then decide what to do about it.
True
False
