Premium Essay

Lp4: Review Questions

In:

Submitted By gothangl
Words 817
Pages 4
1. What is risk management? The process of identifying risk, as represented by vulnerabilities, to an organization’’s information assets and infrastructure, and taking steps to reduce this risk to an acceptable level.

Why is the identification of risks, by listing assets and their vulnerabilities, so important to the risk management process? It is a starting point for the next step in the risk management process –– risk assessment.
2. According to Sun Tzu, what two key understandings must you achieve to be successful in battle? Know the enemy and know yourself.
3. Who is responsible for risk management in an organization? Each community of interest has a role to play in managing the risks that an organization encounters.
Which community of interest usually takes the lead in information security risk management? information security community

4. In risk management strategies, why must periodic review be a part of the process? To verify the completeness and accuracy of the asset inventory, review and verify the threats to and vulnerabilities in the asset inventory, as well as the current controls and mitigation strategies. Must also review the cost effectiveness of each control and revisit decisions on deployment of controls. Managers at all levels must regularly verify the ongoing effectiveness of every control deployed.
5. Why do networking components need more examination from an information security perspective than from a systems development perspective? Networking components need more examination from an information security perspective than from a systems development perspective because networking subsystems are often the focal point of attacks against the system.
6. What value does an automated asset inventory system have for the risk identification process? An automated asset inventory system would be valuable to the risk identification

Similar Documents

Premium Essay

Women Entrepreneurs in Smes Bangladesh Perspective

...6 2.2 2.3 2.4 2.5 2.5.1 2.5.2 2.6 3.0 4.0 4..1 4..2 5.0 5.1 5.2 5.3 5.4 6.0 6.1 6.2 6.3 6.4 6.4.1 6.5 6.6 6.7 6.7.1 6.7.2 7.0 7.1 Introduction Statement of the problem Significance of the study Objective of the study Theoretical perspective of the study Scope of the study Limitations of the study Study Methodology Primary Research Location of the survey Sample Size Support Service Providers Methods of Data Collection Techniques of Data Collection Techniques of Data Analysis Secondary Research Focus Group Discussion (FGD) Key Informant Meeting (KIM) and Preparation of Case Studies Planning Workshops (PW) Planning Workshop Dialogues in the 6 Divisional HQs Discussions at Planning Workshops National Dissemination Seminar (NDS) Literature Review Entrepreneurship Concept of Entrepreneurship: A theoretical discussion Entrepreneurship in Bangladesh Women Entrepreneurship in Bangladesh History of Women Entrepreneurship Development in Bangladesh Women Entrepreneurs of Bangladesh Women Entrepreneurship in Urban Areas Women Entrepreneurship in Rural Areas Small & Medium Enterprises (SMEs) Definition of SME Theories of SME SMEs in Bangladesh Promotion of SMEs for Sustainable Development Access to Finance Barriers to the Promotion of the SME sector in Bangladesh Booster Sectors of SME The program for SME in Bangladesh (Government & NGOs) SME Foundation SME Development through Non-Government Organizations (NGOs) Gender related Issues in SME Development Gender Equality 1 2 2 3 3 3 4 5 5...

Words: 136702 - Pages: 547