MoIS4 CH 09 Review Questions
1. What is competitive advantage? How has it changed in the years since the IT industry began?
An organization has competitive advantage when it creates a business model, method, or
2. What is competitive disadvantage? Why has it emerged as a factor?
Competitive disadvantage is the state of falling behind the competition. Organizations today
3. What are the five risk control strategies presented in this chapter?
4. Describe the strategy of defense.
The risk control strategy of defense is the application of safeguards that eliminate or reduce the
5. Describe the strategy of transferal.
6. Describe the strategy of mitigation.
The risk control strategy of mitigation is the reduction of the impact, should an attacker
7. Describe the strategy of acceptance.
The risk control strategy of acceptance is an understanding of the consequences and
8. Describe residual risk.
9. What four types of controls or applications can be used to avoid risk?
The four broad areas of controlling risk are: use of a control function, accommodation on an
10. Describe how outsourcing can be used for risk transference.
Outsourcing can be used for risk transference when an organization chooses to hire an ISP or a
11. What conditions must be met to ensure that risk acceptance has been used properly?
The following conditions must be met to ensure that risk acceptance has been used properly: The
12. What is risk appetite? Explain why risk appetite varies from organization to organization.
Risk appetite is the amount of risk an organization is willing to accept as it evaluates the trade
off between perfect security and unlimited accessibility. Risk appetite varies from organization
13. What is a cost-benefit analysis?
A cost-benefit analysis is an evaluation of the anticipated losses that could be avoided from a
14. What is the difference between intrinsic value and acquired value?
Intrinsic value is the essential worth of the asset under consideration; acquired value is the value
15. What is single loss expectancy? What is annual loss expectancy?
Single loss expectancy (SLE) is the calculated value associated with a sole occurrence of the
16. What is the difference between benchmarking and baselining?
Benchmarking is the process of comparing one’s company with other companies that are seeking
17. What is the difference between organizational feasibility and operational feasibility?
Organizational feasibility examines how well the proposed InfoSec alternatives will contribute to
18. What is the difference between qualitative measurement and quantitative measurement?
19. What is the OCTAVE Method? What does it provide to those who adopt it?
The OCTAVE Method is an InfoSec risk evaluation methodology that allows organizations to
20. How does Microsoft define “risk management”? What phases are used in its approach?
The Microsoft definition of risk is “the probability of a vulnerability being exploited in the