|
|
Created by Lyndsay Badding
over 2 years ago
|
|
| Question | Answer |
| Phase 1 | identify mission essential functions |
| Phase 2 | identify vulnerabilities |
| Phase 3 | identify threats |
| Phase 4 | analyze business impacts |
| Phase 5 | identify risk response |
| Acceptance | assigning no security control due to high cost, asset's value isn't high enough, or the sec control will cause undue delay |
| Transference | assigning a risk to a third party |
| Avoidance | stop doing a risky activity |
| Mitigation (Remediation) | reducing exposure to risk factors |
| Risk Reduction | set of controls that reduces the likelihood or cost of a risk being realized |
| Risk Register | a document showing risk assessment results these appear in exec briefings and IRP sessions |
Want to create your own Flashcards for free with GoConqr? Learn more.