GRADED A+ (QUESTIONS AND
ANSWERS)
Risk avoidance - Choosing not to engage in activities that could expose your organization to the risk.
Could be restrictive or disruptive.
Risk transference - Transferring some or all of the risk to another party that will assume
responsibility, usually for a direct financial cost. Usually insurance.
Risk mitigation - Applying security controls to reduce risk. Mitigation is distinct from avoidance
because it aims to limit the risk of an activity without preventing the activity outright.
Risk deterrence - Applying visible controls to discourage attacks or human error from occurring int he
first place. Includes bright lights, visible guards, or labeling a high voltage wire.
Risk Acceptance - Hoping for the best without changing anything. Ignoring a risk only counts as
acceptance when you accurately know the inherent risk.
Technology controls - Used to ensure valuable data isn't damaged, rendered unavailable, or leaked.
DLP goals can be achieved using controls like encryption, firewalls, backup systems, and device
hardening.
Policies and procedures - Administrative and operational controls are essential in addition to
technical controls to ensure they're applied consistently and adequately. For example, if your remote
access system requires authentication, without a strong password policy, there's still a high risk of
unauthorized logins.
Routine audits - Periodic review to look for unauthorized changes or unnoticed problems. Can
include reviewing user permissions or security configurations, reviewing security logs to find
suspicious activity, vulnerability assessments, or more.
Incident management - Practices and procedures that govern how an organization will respond to a
security incident, to determine what harm was done, minimize or repair damage, and restore
systems to a secure state.