Chapter 09 – Risk Management: Controlling Risk
TRUE/FALSE
1. The defense risk control strategy may be accomplished by rethinking how services are offered and
outsourcing to other organizations, among other strategies.
2. Risks can be avoided by countering the threats facing an asset or by eliminating the exposure of an
asset.
3. The criterion most commonly used when evaluating a strategy to implement InfoSec controls
and safeguards is economic feasibility.
4. Unlike other risk management frameworks, FAIR relies on the qualitative assessment of many risk
components using scales with value ranges.
5. The ISO 27005 Standard for InfoSec Risk Management includes a five-stage management
methodology; among them are risk treatment and risk communication.
MULTIPLE CHOICE
1. Application of training and education is a common method of which risk control strategy?
a.
mitigation
c.
acceptance
b.
defense
d.
transferal
2. Which of the following describes an organization’s efforts to reduce damage caused by a realized
incident or disaster?
a.
acceptance
c.
transference
b.
avoidance
d.
mitigation
3. Strategies to limit losses before and during a disaster is covered by which of the following plans in the
mitigation control approach?
a.
incident response plan
c.
disaster recovery plan
b.
business continuity plan
d.
damage control plan
4. The only use of the acceptance strategy that industry practices recognize as valid occurs when the
organization has done all but which of the following?
a.
Determined the level of risk posed to the information asset
b.
Performed a thorough cost-benefit analysis
c.
Determined that the costs to control the risk to an information asset are much lower than
the benefit gained from the information asset
d.
Assessed the probability of attack and the likelihood of a successful exploitation of a
vulnerability
5. Which of the following can be described as the quantity and nature of risk that organizations are
willing to accept as they evaluate the trade-offs between perfect security and unlimited accessibility?
a.
residual risk
c.
risk assurance
b.
risk appetite
d.
risk termination
6. Which of the following is NOT a valid rule of thumb on risk control strategy selection?
a.
When a vulnerability exists: Implement security controls to reduce the likelihood of a
vulnerability being exploited.
b.
When a vulnerability can be exploited: Apply layered protections, architectural designs,
and administrative controls to minimize the risk or prevent the occurrence of an attack.
c.
When the attacker’s potential gain is less than the costs of attack: Apply protections to
decrease the attacker’s cost or reduce the attacker’s gain, by using technical or operational
controls.
d.
When the potential loss is substantial: Apply design principles, architectural designs, and
technical and non-technical protections to limit the extent of the attack, thereby reducing
the potential for loss.
7. Which of the following affects the cost of a control?
a.
liability insurance
c.
asset resale
b.
CBA report
d.
maintenance
8. By multiplying the asset value by the exposure factor, you can calculate which of the following?
a.
annualized cost of the safeguard
c.
value to adversaries
b.
single loss expectancy
d.
annualized loss expectancy
9. What is the result of subtracting the post-control annualized loss expectancy and the ACS from the
pre-control annualized loss expectancy?
a.
cost-benefit analysis
c.
single loss expectancy
b.
exposure factor
d.
annualized rate of occurrence
10. Which of the following determines acceptable practices based on consensus and relationships among
the communities of interest.
a.
organizational feasibility
c.
technical feasibility
b.
political feasibility
d.
operational feasibility
11. The Microsoft Risk Management Approach includes four phases. Which of the following is NOT one
of them?
a.
conducting decision support
c.
InfoSec community analysis
b.
implementing controls
d.
measuring program effectiveness
12. What does FAIR rely on to build the risk management framework that is unlike many other risk
management frameworks?
a.
qualitative assessment of many risk
components
c.
subjective prioritization of controls
b.
quantitative valuation of safeguards
d.
risk analysis estimates
13. In which technique does a group rate or rank a set of information, compile the results and repeat until
everyone is satisfied with the result?
a.
OCTAVE
c.
Hybrid Measures
b.
FAIR
d.
Delphi
14. Once a control strategy has been selected and implemented, what should be done on an ongoing basis
to determine their effectiveness and to estimate the remaining risk?
a.
analysis and adjustment
c.
monitoring and measurement
b.
review and reapplication
d.
evaluation and funding
15. Which of the following is a step in Stage 2 – Evaluate Loss Event Frequency of the FAIR risk
management framework?
a.
identify the asset at risk
c.
estimate control strength
b.
estimate probable loss
d.
derive and articulate risk
16. What should each information assetthreat pair have at a minimum that clearly identifies any residual
risk that remains after the proposed strategy has been executed?
a.
probability calculation
c.
risk acceptance plan
b.
documented control strategy
d.
cost-benefit analysis
17. Which of the following is usually determined by valuing the information asset or assets exposed by
the vulnerability and then determining how much of that value is at risk, and how much risk exists for
the asset.
a.
feasibility
c.
cost
b.
valuation
d.
benefit
18. Which of the following is NOT an alternative to using CBA to justify risk controls?
a.
benchmarking
c.
selective risk avoidance
b.
due care and due diligence
d.
the gold standard
19. The ISO 27005 Standard for Information Security Risk Management includes five stages including all
but which of the following?
a.
risk assessment
c.
risk communication
b.
risk treatment
d.
risk determination
20. The NIST risk management approach includes all but which of the following elements?
a.
inform
c.
frame
b.
assess
d.
respond
COMPLETION
1. The risk control strategy that seeks to reduce the impact of a successful attack through the use of IR,
DR and BC plans is ____________________ .
2. The ____________________ risk control strategy attempts to shift the risk to other assets, processes,
or organizations.
3. The __________ level and an asset’s value should be a major factor in the risk control strategy
selection.
4. The goal of InfoSec is not to bring residual risk to zero; rather, it is to bring residual risk in line with
an organization’s risk ___________.
5. When a vulnerability (flaw or weakness) exists in an important asset, implement security controls to
reduce the likelihood of a vulnerability being ___________.
MATCHING
a.
defense risk control strategy
f.
cost-benefit analysis
b.
mitigation risk control strategy
g.
cost avoidance
c.
acceptance risk control strategy
h.
asset valuation
d.
termination risk control strategy
i.
organizational feasibility
e.
risk appetite
j.
single loss expectancy
1. a form of feasibility study that compares the life-cycle cost of implementing a control mechanism
against the estimated economic benefit
2. a conscious decision to do nothing to protect an information asset from risk, and to accept the outcome
from any resulting exploitation
3. a mechanism to control risk by the prevention of an exploitation of a vulnerability
4. a process of assigning financial value or worth to each information asset
5. the quantity and nature of risk that organizations are willing to accept
6. examines how well the proposed InfoSec alternatives will contribute to the efficiency, effectiveness,
and overall operation of an organization
7. an approach to control risk by attempting to reduce the impact of the loss caused by a realized incident
8. the calculated value associated with the most likely loss from a single occurrence of a specific attack
9. the money saved by using the defense strategy via the implementation of a control
10. a choice not to protect an asset and the removal of it from the environment that represents risk
SHORT ANSWER
1. Briefly describe the five basic strategies to control risk that result from vulnerabilities.
2. Discuss three alternatives to feasibility analysis.
3. Explain two practical guidelines to follow in risk control strategy selection.
4. Once an organization has estimated the worth of various assets, what three questions must be asked to
calculate the potential loss from the successful exploitation of a vulnerability?
5. What does the result of a CBA determine? What is the formula for the CBA?
6. Describe operational feasibility.
7. Describe the use of hybrid assessment to create a quantitative assessment of asset value.
8. What is the OCTAVE method approach to risk management?
9. What are the four phases of the Microsoft risk management strategy?
10. What are the four stages of a basic FAIR analysis?