What makes a situation a security risk?
A risk exists when a threat could exploit a weakness and cause harm.
Study 8 Security in Practice with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What makes a situation a security risk?
A risk exists when a threat could exploit a weakness and cause harm.
What should an asset-and-impact assessment establish?
Identify what could be harmed—such as data, services, people, finances, or reputation—and how serious the harm would be.
What do threat and likelihood describe?
Identify the event that could cause harm and judge how plausible it is in the system.
How do vulnerability and exposure differ?
A vulnerability is a weakness that could let an event succeed; exposure describes how accessible it is to a threat source.
What are the four ways to respond to a significant risk?
Choose to mitigate the risk, avoid the activity, transfer or share some consequences, or accept the remaining risk.
What is residual risk?
Residual risk is the risk that remains after safeguards are applied; decide explicitly whether it is acceptable.
What is defense in depth?
Defense in depth combines multiple, varied safeguards across people, technology, and operations so security does not rely on one barrier.
How can security layers limit harm when one control fails?
If multifactor authentication blocks a stolen-password login, access limits can still constrain a compromised account, while monitoring may reveal suspicious activity.
How should account access be limited?
Give each account only the access its tasks require, and promptly remove access that is no longer needed.
What kind of evidence helps verify that safeguards work?
Check evidence such as configuration records or a test restore, rather than relying only on written policies.
What does tracing likely threat paths involve?
Trace how an attacker, mistake, or outage could affect the system—for example, phishing that leads to account compromise.
What are the six functions of NIST's Cybersecurity Framework?
Govern, Identify, Protect, Detect, Respond, and Recover.