BCLE 2000 EVALUATION TEST QUESTIONS AND
ANSWERS SURE A+
✔✔What are the important concepts from lesson one? - ✔✔- Establish need for BC
- Gain leadership support
- Develop program management
- Assign responsibilities
- Create a steering committee
✔✔What is the professionals role in the risk assessment? - ✔✔1. Work with leadership
and any risk management groups to gain agreement on a risk management
methodology.
2. Identify develop and implement information gathering activities across the entity to
identify risks.
3. Determine the probability and impact of the identified risks
4. Evaluate the impact of risks on those factors that are essential to conducting the
entities operations.
5. Identify and evaluate the effectiveness of controls, employed to reduce the impact of
exposures.
6. Document and present the risk and vulnerability assessment and recommend
recommendations to leadership before approval
7. Request approval from leadership to develop the entities risk appetite.
✔✔What are the two threat sources? - ✔✔External and internal threats
✔✔What are the recommended changes to controls for reducing impact? - ✔✔- physical
protection, including access control
- logical protection, including cyber security, data, access, and backups
- location of assets
- personnel procedures, including training
- utilities
, ✔✔Who should the results of a risk assessment be presented to? - ✔✔Steer
co/leadership
✔✔what's an important step when requesting approval from leadership of a risk
assessment? - ✔✔Ensuring to document what things leadership does not approve and
why
✔✔What is a threat? - ✔✔A person condition or incident likely to cause damage or
danger
✔✔What is probability? - ✔✔The likelihood that the threat will become a reality
✔✔What is a control? - ✔✔The means of managing risk
✔✔What is vulnerability? - ✔✔The susceptibility of a threat becoming a reality
✔✔What is impact? - ✔✔The effect of an event
✔✔What is risk transfer? - ✔✔The contractual shifting of a risk from one party to
another. I.e. insurance.
✔✔What is risk? - ✔✔The consequences of a threat becoming a reality
✔✔What are characteristics of systemic risk? - ✔✔- highly interconnected
- global in nature
- non-linear in cause effect relationships
- very hard to predict
- usually has a tipping point where it Cascades
- random in nature
✔✔What is risk management? - ✔✔- Acceptance/tolerance
- prevention/mitigation
- risk retention
- Risk transfer
✔✔What is the risk assessment and management process? - ✔✔1. Organizational
context
2. Risk identification
3. Risk Assessment
4. Risk evaluation
5. Risk treatment
6. Monitoring review and corrective action
7. Communication
ANSWERS SURE A+
✔✔What are the important concepts from lesson one? - ✔✔- Establish need for BC
- Gain leadership support
- Develop program management
- Assign responsibilities
- Create a steering committee
✔✔What is the professionals role in the risk assessment? - ✔✔1. Work with leadership
and any risk management groups to gain agreement on a risk management
methodology.
2. Identify develop and implement information gathering activities across the entity to
identify risks.
3. Determine the probability and impact of the identified risks
4. Evaluate the impact of risks on those factors that are essential to conducting the
entities operations.
5. Identify and evaluate the effectiveness of controls, employed to reduce the impact of
exposures.
6. Document and present the risk and vulnerability assessment and recommend
recommendations to leadership before approval
7. Request approval from leadership to develop the entities risk appetite.
✔✔What are the two threat sources? - ✔✔External and internal threats
✔✔What are the recommended changes to controls for reducing impact? - ✔✔- physical
protection, including access control
- logical protection, including cyber security, data, access, and backups
- location of assets
- personnel procedures, including training
- utilities
, ✔✔Who should the results of a risk assessment be presented to? - ✔✔Steer
co/leadership
✔✔what's an important step when requesting approval from leadership of a risk
assessment? - ✔✔Ensuring to document what things leadership does not approve and
why
✔✔What is a threat? - ✔✔A person condition or incident likely to cause damage or
danger
✔✔What is probability? - ✔✔The likelihood that the threat will become a reality
✔✔What is a control? - ✔✔The means of managing risk
✔✔What is vulnerability? - ✔✔The susceptibility of a threat becoming a reality
✔✔What is impact? - ✔✔The effect of an event
✔✔What is risk transfer? - ✔✔The contractual shifting of a risk from one party to
another. I.e. insurance.
✔✔What is risk? - ✔✔The consequences of a threat becoming a reality
✔✔What are characteristics of systemic risk? - ✔✔- highly interconnected
- global in nature
- non-linear in cause effect relationships
- very hard to predict
- usually has a tipping point where it Cascades
- random in nature
✔✔What is risk management? - ✔✔- Acceptance/tolerance
- prevention/mitigation
- risk retention
- Risk transfer
✔✔What is the risk assessment and management process? - ✔✔1. Organizational
context
2. Risk identification
3. Risk Assessment
4. Risk evaluation
5. Risk treatment
6. Monitoring review and corrective action
7. Communication