MoIS4 CH 08 Review Questions
1. What is risk management?
Answer: Risk management is the process of discovering and assessing the risks to an
2. List and describe the key areas of concern for risk management.
3. Why is identification of risks, through a listing of assets and their vulnerabilities, so
important to the risk management process?
4. According to Sun Tzu, what two things must be achieved to secure information assets
successfully?
Answer: To reduce risk in an organization, the organization must know itself (including the
5. Who is responsible for risk management in an organization?
6. Which community of interest usually takes the lead in information asset risk
management?
Answer: The community that usually takes the lead in information asset risk management is
7. Which community of interest usually provides the resources used when undertaking
information asset risk management?
8. In risk management strategies, why must periodic reviews be a part of the process?
Answer: Periodic reviews must be a part of the risk management strategies because threats
9. Why do networking components need more examination from an InfoSec perspective
than from a systems development perspective?
Answer: Networking components need more examination from an InfoSec perspective than
10. What value would an automated asset inventory system have for the risk identification
process?
Answer: An automated asset inventory system would be valuable to the risk identification
11. Which information attributes are seldom or never applied to software elements?
Answer: Information attributes not often tracked for software, including:
12. Which information attribute is often of great value for networking equipment when
Dynamic Host Configuration Protocol (DHCP) is not used?
13. When you document procedures, why is it useful to know where the electronic versions
are stored?
14. Which is more important to the information asset classification scheme, that it be
comprehensive or that it be mutually exclusive?
Answer: A comprehensive information asset classification scheme is more desirable since
15. What is the difference between an asset’s ability to generate revenue and its ability to
generate profit?
16. How many categories should a data classification scheme include? Why?
Answer: An organization would need as many categories as necessary to include all of the
17. How many threat categories are listed in this chapter? Which is noted as being the most
frequently encountered, and why?
Answer: There are 12 threat categories discussed in the chapter. The most frequently
18. What are vulnerabilities?
19. Describe the TVA worksheet. What is it used for?
Answer: The TVA worksheet combines a prioritized list of assets and their vulnerabilities
20. Examine the simplest risk formula presented in this chapter. What are its primary
elements?