1. What is the pur- • Identify assets requiring protection and/or that are impor-
pose of the asset tant to the organization and to national security
assessment • Identify undesirable events and expected impacts
step of the • Prioritize assets based on consequences of loss
risk management
process?
2. What is the pur- • Determine threats to identified assets
pose of the threat • Assess intent and capability of identified threats
assessment • Assess current threat level for the identified assets
step of the
risk management
process?
3. What is the pur- • Identify existing countermeasures and their level of effec-
pose of the vul- tiveness in reducing vulnerabilities
nerability • Identify potential vulnerabilities related to identified as-
assessment step sets and their undesirable events
of the risk man- • Identify current vulnerability level for the identified assets
agement that can be exploited by the identified threats
process?
4. What is the pur- • Integrate information about the impact of undesirable
pose of the events (collected during the asset assessment step) and
risk assessment the likelihood of undesirable events (based on information
step of the collected during the threat and vulnerability assessment
risk management steps) to determine risks to identified assets
process?
5. What is the • Identify potential countermeasures to reduce vulnerabil-
purpose of ity and/or threat and/or impact
the countermea- • Identify countermeasure benefits in terms of risk reduc-
sure determina- tion
tion step of the • Identify countermeasure costs
risk management • Conduct cost/benefit analysis
process? • Prioritize options and prepare recommendation for deci-
sion maker
6.
1/6
, Security Program Integration Professional Certification (SPIPC) Exam
What is the pri- • National-level security policy endorses a holistic risk
mary benefit of management approach, allowing decision makers to ef-
conducting the fectively allocate resources that provide the necessary
risk management security to assets that match the threat to those assets
process?
7. What are the pri- • Time and effort necessary to execute the five steps of the
mary costs of risk management process
conducting the
risk management
process?
8. What are the • Availability of information necessary to accurately deter-
potential chal- mine the likelihood and impact of undesirable events
lenges secu-
rity practition-
ers may face
when enacting
the risk manage-
ment process?
9. Where can we get • Self-inspections
information to
evaluate an orga-
nization's com-
pliance with se-
curity policies?
10. Where can we • Incident reports
get information • Regressive analysis
to evaluate the • SME interviews (individuals involved in protecting Clas-
effectiveness of sified Military Information (CMI))
an organization's • Security planning documents
security pro- • Surveys and audits
gram? • Information Systems (IS) Certification and Accreditation
documentation
• Facility certification and accreditation documentation
11. Given the inci- • The appropriate signage and notices are posted in ap-
dent, what is an propriate areas, but are potentially ineffective considering
2/6