Chapter 08 – Risk Management: Identifying and Assessing Risk
TRUE/FALSE
1. Having an established risk management program means that an organization’s assets are completely
protected.
2. The InfoSec community often takes on the leadership role in addressing risk.
3. MAC addresses are considered a reliable identifier for devices with network interfaces, since they are
essentially foolproof.
4. Some threats can manifest in multiple ways, yielding multiple vulnerabilities for an asset-threat pair.
5. The Australian and New Zealand Risk Management Standard 4360 uses qualitative methods to
determine risk based on a threat’s probability of occurrence and expected results of a successful attack.
MULTIPLE CHOICE
1. Each manager in the organization should focus on reducing risk. This is often done within the context
of one of the three communities of interest, which includes all but which of the following?
a.
General management must structure the IT
and InfoSec functions
c.
Executive management must develop
corporate-wide policies
b.
IT management must serve the IT needs of
the broader organization
d.
InfoSec management must lead the way
with skill, professionalism, and flexibility
2. The identification and assessment of levels of risk in an organization describes which of the following?
a.
Risk analysis
c.
Risk assessment
b.
Risk identification
d.
Risk reduction
3. Two of the activities involved in risk management include identifying risks and assessing risks.
Which of the following activities is part of the risk assessment process?
a.
Creating an inventory of information assets
b.
Classifying and organizing information assets into meaningful groups
c.
Assigning a value to each information asset
d.
Calculating the risks to which assets are exposed in their current setting
4. Two of the activities involved in risk management include identifying risks and assessing risks. Which
of the following activities is part of the risk identification process?
a.
Determining the likelihood that vulnerable systems will be attacked by specific threats
b.
Calculating the risks to which assets are exposed in their current setting
c.
Assigning a value to each information asset
d.
Documenting and reporting the findings of risk identification and assessment
5. Which of the following is a network device attribute that may be used in conjunction with DHCP,
making asset-identification using this attribute difficult?
a.
part number
c.
MAC address
b.
serial number
d.
IP address
6. Which of the following is a network device attribute that is tied to the network interface?
a.
serial number
c.
IP address
b.
MAC address
d.
model number
7. Which of the following attributes does NOT apply to software information assets?
a.
Serial number
c.
Manufacturer name
b.
Controlling entity
d.
Physical location
8. Which of the following distinctly identifies an asset and can be vital in later analysis of threats directed
to specific models of certain devices or software components?
a.
Name
c.
Serial number
b.
MAC address
d.
Manufacturer’s part number
9. Asset classification schemes should categorize information assets based on which of the following?
a.
value and uniqueness
c.
cost and replacement value
b.
sensitivity and security needs
d.
ease of reproduction and fragility
10. Classification categories must be mutually exclusive and which of the following?
a.
repeatable
c.
comprehensive
b.
unique
d.
selective
11. What is the final step in the risk identification process?
a.
assessing values for information assets
c.
identifying and inventorying assets
b.
classifying and categorizing assets
d.
listing assets in order of importance
12. Once an information asset is identified, categorized, and classified, what must also be assigned to it?
a.
asset tag
c.
location ID
b.
relative value
d.
threat risk
13. What should you be armed with to adequately assess potential weaknesses in each information asset?
a.
properly classified inventory
c.
intellectual property assessment
b.
audited accounting spreadsheet
d.
list of known threats
14. Which of the following is an example of a technological obsolescence threat?
a.
hardware equipment failure
c.
outdated servers
b.
unauthorized access
d.
malware
15. Determining the cost of recovery from an attack is one calculation that must be made to identify risk,
what is another?
a.
cost of prevention
c.
cost of prosecution
b.
cost of litigation
d.
cost of identification
16. What is defined as specific avenues that threat agents can exploit to attack an information asset?
a.
liabilities
c.
vulnerabilities
b.
defenses
d.
weaknesses
17. What should the prioritized list of assets and their vulnerabilities and the prioritized list of threats
facing the organization be combined to create?
a.
risk exposure report
c.
costs-risks-prevention database
b.
threats-vulnerabilities-assets worksheet
d.
threat assessment catalog
18. The likelihood of the occurrence of a vulnerability multiplied by the value of the information asset
minus the percentage of risk mitigated by current controls plus the uncertainty of current knowledge of
the vulnerability is the definition of which of the following?
a.
vulnerability mitigation controls
c.
exploit likelihood equation
b.
risk assessment factors
d.
attack analysis calculation
19. An estimate made by the manager using good judgement and experience can account for which factor
of risk assessment?
a.
risk determination
c.
likelihood and consequences
b.
assessing potential loss
d.
uncertainty
20. Which of the following is NOT among the typical columns in the ranked vulnerability risk worksheet?
a.
uncertainty percentage
c.
risk-rating factor
b.
asset impact
d.
vulnerability likelihood
1. Risk ____________ is the process of discovering and assessing the risks to an organization’s
operations and determining how those risks can be mitigated.
2. Assessing risks includes determining the ____________________ that vulnerable systems will be
attacked by specific threats.
3. Classification categories must be ____________________ and mutually exclusive.
4. As each information asset is identified, categorized, and classified, a ________ value must also be
assigned to it.
5. As part of the risk identification process, listing the assets in order of importance can be achieved by
using a weighted ____________________ worksheet.
MATCHING
a.
risk management
f.
threat identification
b.
risk analysis
g.
TVA worksheet
c.
classification categories
h.
qualitative risk assessment
d.
risk identification
i.
residual risk
e.
field change order
j.
ranked vulnerability risk worksheet
1. occurs when a manufacturer performs an upgrade to a hardware component at the customer’s premises
2. process that identifies vulnerabilities in an organization’s information system
3. the prioritized list of threats is placed along the vertical axis
4. columns include asset impact, vulnerability, and risk-rating factor
5. identification and assessment of levels of risk in the organization
6. remains even after the existing control has been applied
7. process of discovering the risks to an organization’s operations
8. assessment of potential weaknesses in each information asset
9. performed using categories instead of specific values to determine risk
10. must be comprehensive and mutually exclusive
SHORT ANSWER
1. Briefly describe any three standard categories of information asset and their respective risk
management components.
2. For the purposes of relative risk assessment how is risk calculated?
3. List the stages in the risk identification process in order of occurrence.
4. What does it mean to ‘know the enemy’ with respect to risk management?
5. What strategic role do the InfoSec and IT communities play in risk management? Explain.
6. What are the included tasks in the identification of risks?
7. Describe the use of an IP address when deciding which attributes to track for each information asset.
8. How should the initial inventory be used when classifying and categorizing assets?
9. Why is threat identification so important in the process of risk management?
10. Discuss the trends in frequency of attacks and how that plays into a risk management strategy.