1. a form of feasibility study that compares the life-cycle cost of implementing a control mechanism
against the estimated economic benefit
2. a conscious decision to do nothing to protect an information asset from risk, and to accept the outcome
from any resulting exploitation
3. a mechanism to control risk by the prevention of an exploitation of a vulnerability
4. a process of assigning financial value or worth to each information asset
5. the quantity and nature of risk that organizations are willing to accept
6. examines how well the proposed InfoSec alternatives will contribute to the efficiency, effectiveness,
and overall operation of an organization
7. an approach to control risk by attempting to reduce the impact of the loss caused by a realized incident
8. the calculated value associated with the most likely loss from a single occurrence of a specific attack
9. the money saved by using the defense strategy via the implementation of a control
10. a choice not to protect an asset and the removal of it from the environment that represents risk
SHORT ANSWER
1. Briefly describe the five basic strategies to control risk that result from vulnerabilities.
2. Discuss three alternatives to feasibility analysis.