Cyber Security Risk Assessment Training/ Exam Review Questions And Answers, Graded A+
CYBER SECURITY RISK ASSESSMENT TRAINING/ EXAM REVIEW QUESTIONS AND ANSWERS, GRADED A+ What are common sources of regulatory drivers for cyber security? - -Laws, regulations, industry/trade groups What are some negative consequences of failing to implement effective cyber security? - -Criminal prosecution, civil liability, loss of confidence What are the Generally Accepted System Security Principles (GASSP)? - -Fundamental principles describing responsible cyber security NIST SP 800-53 is popular in the U.S. What international standard is highly compatible with SP 800-53? - -ISO27001 What are the four principles of Operational Risk Management (ORM)? - -Accept risk when benefits outweigh the risk; Accept no unnecessary risk; Anticipate and manage risk through planning; Make decisions at the right level Name the three levels of ORM decision-making. - -In-Depth, Deliberate, Time-Critical Define risk. - -Risk is the "level of impact on organizational operations resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occurring." Give several example of vulnerabilities in the context of cyber security - -Defective software, bad system design, ineffective or badly implemented controls.
Document information
- Uploaded on
- April 10, 2024
- Number of pages
- 5
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers