← All SSP Flashcard Decks

Risk Evaluation & Management Flashcards

7 cards from real SSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Evaluation & Management flashcards as text
  1. Under the NIST Risk Management Framework (RMF), what is the purpose of the 'Authorize' step?

    Answer: A senior official formally accepts the risk of operating an information system based on the implemented controls

    In NIST RMF, the Authorize step requires an Authorizing Official to review residual risk and formally accept it before system operation.

  2. A security practitioner is applying ISO 31000 principles. Which statement BEST reflects the standard's view on risk management integration?

    Answer: Risk management should be embedded in all organizational processes and decision-making, not siloed in a security department

    ISO 31000 emphasizes that risk management must be integrated into the organization's governance, strategy, planning, and operations—not treated as a separate function.

  3. An organization conducts a Failure Mode and Effects Analysis (FMEA) on a physical access control system. What is the PRIMARY output of this analysis?

    Answer: A prioritized list of failure modes ranked by their severity, occurrence frequency, and detectability

    FMEA produces a risk priority number (RPN) for each failure mode by combining severity, occurrence, and detection ratings to drive mitigation priorities.

  4. A practitioner is evaluating supply chain risk. A critical vendor processes sensitive personnel data. The vendor's SOC 2 Type II report is 18 months old. What risk does this present?

    Answer: The report may not reflect the vendor's current control environment, leaving undetected gaps

    An 18-month-old SOC 2 report may not capture control changes, incidents, or new risks, creating uncertainty about current control effectiveness.

  5. When applying the 'bowtie' risk analysis model, what do the LEFT side and RIGHT side of the bowtie represent respectively?

    Answer: Threat sources and causes (left) versus consequences and impacts (right), with the 'knot' being the risk event

    The bowtie model maps causes and threats on the left, the unwanted event at the center knot, and consequences with recovery controls on the right.

  6. An organization's risk appetite statement says it will 'accept risks up to $500,000 ALE without mandatory escalation.' A new risk is calculated at $650,000 ALE. Which action is REQUIRED?

    Answer: The risk must be escalated to senior leadership or the board for a treatment or acceptance decision

    The risk appetite statement defines the escalation trigger; a $650,000 ALE exceeds the $500,000 threshold and mandates senior leadership review.

  7. What distinguishes a 'risk scenario' from a simple 'threat statement' in enterprise risk management?

    Answer: A risk scenario combines a threat actor, a threat event, a vulnerable asset, and a potential impact into a narrative

    Risk scenarios are structured narratives integrating threat source, event, asset, and impact to make risks concrete and actionable for decision-makers.