- Study guides, Class notes & Summaries
Looking for the best study guides, study notes and summaries about ? On this page you'll find 51 study documents about .
51 results
Exam (elaborations)
MIS 416 Exam 2 Final (with 100% Accurate Answers)
The organizations level of security risk acceptance should be considered when selecting recommended safeguards. correct answers True 
 
Which of the following orders is consistent with the KPI, KPX, and KRI formation? correct answers metrics, KPI, KPx, KRI, Dashboard 
 
Which phase of the information security measurement system lifecycle involves gaining a solid appreciation of the organization information security-related information needs? correct answers Phase 1 
 
Risk monitoring provides or...
Exam (elaborations)
MIS 416 Exam 2/Final (100% Errorless Solutions)
Place the following in the correct order for risk management. 
A) rank risks 
B) analyze risks 
C) identify risk 
D) treat risks 
E) monitor and review risks correct answers C B A D E 
 
Clear and effective security risk assessment reporting requires that the contents of the report be perceived as (check all that apply) 
A) unambiguous 
B) nonthreatening 
C) accurate 
D) relevant 
E) actionable correct answers A B C D 
 
Which of the following can affect the state of risks? 
A) Risk levels of co...
Exam (elaborations)
MIS 416 EXAM 2 (100% Verified Solutions)
What type of control ensures that account management is secure? 
 
A. access management controls 
 
B. access controls 
 
C. account management controls 
 
D. account controls correct answers C 
 
ROSI = reduction in risk exposure / investment in countermeasures 
 
T/F correct answers T 
 
Which of the following affects the cost of a control? 
 
A. maintenance 
 
B. CBA report 
 
C. asset resale 
 
D. liability insurance correct answers A 
 
As a top-level executive at your own company, yo...
Exam (elaborations)
MIS 416 Exam 2 (with Complete Solutions)
The organizations level of security risk acceptance should be considered when selecting recommended safeguards. correct answers True 
 
Which of the following orders is consistent with the KPI, KPX, and KRI formation? correct answers metrics, KPI, KPx, KRI, Dashboard 
 
Which phase of the information security measurement system lifecycle involves gaining a solid appreciation of the organization information security-related information needs? correct answers Phase 1 
 
Risk monitoring provides or...
Exam (elaborations)
MIS 416 Exam 1 Quiz 2 & 3 (100% Errorless)
The RIIOT technique can be used with any set of security document requirements, standards or guidelines. (T/F) correct answers True 
 
According to Talabis, what is the function of a BIA? 
 
 
To assess and identify critical and non-critical organizational functions and activities. 
 
 
To evaluate what threats are specific to each business organization unit in a company and how these threats will specifically impact the business unit. 
 
 
To identify what business processes are going to be m...
Exam (elaborations)
MIS 416 Exam #2 Study Guide (All Correct)
Logs need to be reviewed. (T/F) correct answers True 
 
What type of control ensures that account management is secure? correct answers account management controls 
 
You have created a risk assessment, and management has approved it. What do you do next? correct answers Create a risk mitigation plan. 
 
Which of the following describes an organization's efforts to reduce damage caused by a realized incident or disaster? correct answers mitigation 
 
What is a significant part of the step of ev...
Exam (elaborations)
MIS 416 Exam 1 (A+ Guaranteed)
BIA stands for ___________. correct answers Business impact analysis 
 
The two primary steps you need to complete before progressing with an RA are defining the assessment and reviewing previous findings. correct answers True 
 
Malignant Threats are threats that are always present. correct answers True 
 
RPO stands for ____________. correct answers Recovery point objective 
 
A BIA typically identifies the customers and how the organization plans to serve them correct answers False 
 
RTO sta...
Exam (elaborations)
MIS 416 Study Guide (A+ Graded)
The intangible value of an asset is NOT relevant to managing risks because there is no way to quantify its value in terms of monetary value during a risk assessment. 
 
True 
False correct answers False 
 
A business impact analysis is concerned with identifying and implementing recovery methods. 
 
True 
False correct answers False 
 
According to FAIR, gathering insight into forms of loss from _____, increases the quality of the overall analysis. 
 
A. the internet 
B. similar companies 
C...
Exam (elaborations)
MIS 416 Exam 1 (100% Correct)
RTO stands for correct answers Recovery Time Objective 
 
If you know a single loss expectancy is $100 and the associated annualized rate of occurrence is 5, then what is the annual loss expectancy? correct answers $500 
 
Malignant Threats are threats that are always present. correct answers True 
 
What is NOT an indirect cost? correct answers costs to re-create or recover data 
 
Risk management choices are made in a top-down fashion affecting the sensitivity of risk throughout the organizati...
Exam (elaborations)
MIS 416 EXAM 1 (100% Verified)
___ is the negative result if the risk occurs correct answers impact 
 
The internal LAN is always considered a trusted zone correct answers False 
 
Risk ___ is a process of discovering & assessing theorists to an organizations operations & determining how those risks can be mitigated correct answers management 
 
A (n) ___ is a potential weakness in an asset or its defensive controls correct answers Vulnerability 
 
A(n) __ is a common type of attack to deny service on Internet-facing servers....
Exam (elaborations)
MIS 416 Exam 1 (100% Accurate)
Which of the following can be calculated using the values from an annualized rate of occurrence multiplied by the values from a single loss expectancy? 
A) cost benefit analysis 
B) annualized loss expectancy 
C) asset valuation 
D) operational feasibility correct answers B 
 
What is an indirect objective of a business impact analysis? 
A) to evaluate the effectiveness of controls 
B) to justify funding 
C) to calculate MAOs 
D) to identify an impact that can result from disruptions in a busine...