CPI Risk Assessment & Threat Analysis Flashcards
6 cards from real CPI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CPI Risk Assessment & Threat Analysis flashcards as text
Which risk assessment methodology uses a 3×3 or 5×5 matrix to plot likelihood against consequence?
Answer: Qualitative Risk Matrix
A qualitative risk matrix plots likelihood on one axis and consequence on the other to visually prioritize risks without requiring precise numerical data.
A CPI is asked to assess the 'criticality' of assets during a risk assessment. What does criticality measure?
Answer: The importance of an asset to the organization's mission and the impact if it were lost or compromised
Criticality reflects how essential an asset is to operations and how severely its loss would impact the organization's ability to function.
What is 'vulnerability' in the context of a security risk assessment?
Answer: A weakness or gap in security measures that could be exploited by a threat
Vulnerability is a weakness or deficiency in physical, procedural, or technical security that increases the probability a threat can cause harm.
During a threat analysis, a CPI reviews crime statistics for the area surrounding a facility. This activity supports which step of the risk assessment process?
Answer: Threat identification and likelihood estimation
Historical crime data provides an empirical basis for estimating the likelihood of criminal threats against a facility in a specific location.
What is the primary purpose of a 'residual risk' evaluation after security countermeasures have been implemented?
Answer: To measure the risk that remains after controls have been applied, ensuring it is acceptable to the organization
Residual risk is the remaining exposure after controls are applied; it must be evaluated to confirm it falls within the organization's risk tolerance.
A CPI finds that a chemical storage facility has no documented Business Continuity Plan (BCP). Why is this significant to the risk assessment?
Answer: Without a BCP, the organization cannot recover effectively from incidents, increasing the overall impact of any realized risk
A BCP reduces the consequence component of risk by ensuring the organization can maintain or quickly restore critical operations after a disruptive event.