Exam 7: Risk Management: Controlling Risk

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A risk control strategy that attempts to eliminate or reduce any remaining uncontrolled risk through the application of additional controls and safeguards.

(Multiple Choice)
4.9/5
(33)

Due care and due diligence occur when an organization adopts a certain minimum level of security-that is,what any prudent organization would do in similar circumstances.

(True/False)
4.8/5
(40)

An examination of how well a particular solution is supportable given the organization's current technological infrastructure and resources,which include hardware,software,networking,and personnel is known as operational feasibility.

(True/False)
4.9/5
(29)

What does the result of a CBA determine?  What is the formula for the CBA?

(Essay)
4.9/5
(41)

Describe the use of hybrid assessment to create a quantitative assessment of asset value.

(Essay)
4.8/5
(35)

A risk control strategy that attempts to reduce the impact of the loss caused by a realized incident,disaster,or attack through effective contingency planning and preparation.

(Multiple Choice)
4.9/5
(35)

What are the four phases of the Microsoft risk management strategy?

(Essay)
4.8/5
(32)

Which of the following can be described as the quantity and nature of risk that organizations are willing to accept as they evaluate the trade-offs between perfect security and unlimited accessibility? 

(Multiple Choice)
4.9/5
(40)

In which technique does a group rate or rank a set of information,compile the results and repeat until everyone is satisfied with the result? 

(Multiple Choice)
4.8/5
(26)

Unlike other risk management frameworks,FAIR relies on the qualitative assessment of many risk components using scales with value ranges.

(True/False)
4.8/5
(35)

A risk control strategy that indicates the organization is willing to accept the current level of risk and that the organization makes a conscious decision to do nothing to protect an information asset from risk and to accept the outcome from any resulting exploitation.

(Multiple Choice)
4.8/5
(43)

Risks can be avoided by countering the threats facing an asset or by eliminating the exposure of an asset.

(True/False)
4.8/5
(38)

What should each information asset-threat pair have at a minimum that clearly identifies any residual risk that remains after the proposed strategy has been executed? 

(Multiple Choice)
4.7/5
(36)

The risk control strategy that attempts to reduce the impact of the loss caused by a realized incident,disaster,or attack through effective contingency planning and preparation is known as the mitigation risk control strategy.

(True/False)
4.8/5
(30)

​The risk control strategy that indicates the organization is willing to accept the current level of risk.As a result,the organization makes a conscious decision to do nothing to protect an information asset from risk and to accept the outcome from any resulting exploitation is known as the termination risk control strategy.

(True/False)
4.8/5
(36)

The financial savings from using the defense risk control strategy to implement a control and eliminate the financial ramifications of an incident.

(Multiple Choice)
4.9/5
(35)

​Also known as an economic feasibility study,the formal assessment and presentation of the economic expenditures needed for a particular security control,contrasted with its projected value to the organization is known as cost-benefit analysis (CBA).

(True/False)
4.9/5
(40)

What does FAIR rely on to build the risk management framework that is unlike many other risk management frameworks? 

(Multiple Choice)
4.9/5
(40)

A benchmark is derived by comparing measured actual performance against established standards for the measured category.

(True/False)
4.8/5
(42)

The goal of InfoSec is not to bring residual risk to zero; rather,it is to bring residual risk in line with an organization's risk ___________.

(Short Answer)
4.9/5
(38)
Showing 41 - 60 of 60
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)