What costs should be considered in a cost-benefit analysis?
Technology costs,
Opportunity costs,
Process impact costs,
Time costs,
Personnel costs,
Overall capability costs.
What is the cost-of-loss formula to calculate an asset value?
K = Cp + Ct + Cr + Ci – I
K = total cost of loss
Cp = cost of permanent replacement
Ct = cost of temporary substitute
Cr = total related costs (remove old asset, install new, etc.)
Ci = lost income cost
I = available insurance or indemnity
How is security risk calculated for an individual asset?
Asset value rating X Threat likelihood rating X Severity of incident rating X Vulnerability rating = Security risk rating
5 Major Areas in developing a BCP (Businesss Continuity Plan)
Phase 1
Preparedness/Readiness
Prevention
Response
Recovery
Phase 2
Testing, Training, Evaluating, & Maintenance
BCP Phase 1-Preparedness/Readines
BCP Phase 1-Prevention
BCP Phase 1-Response
BCP Phase 1-Recovery
BCP Phase 2-Testing, Training, Evaluating, and Maintenance
What four criteria can be used to rank assets based on criticality?
Workforce- # and type of workforce located onsite
Service delivery - % of overall service delivery that the asset is responsible for
Dependencies - importance of the asset to other assets
Mission/objectives - overall importance of the asset to the business mission or objective
What are the technical criteria of the Security Metrics Evaluation Tool (Security MET)?
Reliability,
Validity,
Generalizability.
What are the operational criteria of the Security Metrics Evaluation Tool (Security MET)?
Cost,
Timeliness,
Manipulation.
What are the strategic criteria of the Security Metrics Evaluation Tool (Security MET)?
ROI,
Organizational relevance,
Communications.
What are the evaluation criteria for the Security Metrics Evaluation Tool (Security MET).
Technical criteria,
Operational criteria,
Strategic criteria.
How is risk calculated?
Risk = (Threat x Vulnerability x Impact) / 3
What are the two foundational design principles?
The Four Ds and Layered security (aka Defense in Depth)
What equation is used for calculating risk when developing a design?
Risk = Vulnerability x Threat x Asset Value