Introduction to Key Terminology


  • Risk. A risk is a situation or outcome that will have a negative effect. It is always associated with a negative outcome; otherwise it cannot be considered to be a risk.

  • Source of Risk. Source of risk is an event or circumstance that gives rise to a risk or changes the potential impact of a risk or changes the probability that a risk will occur.

  • Threat. A threat is the potential or capacity to inflict harm. It is the person or thing that will cause the dollar impact if the risk matures.

  • Vulnerability. A vulnerability is something inherent or intrinsic to the risk situation that introduces a weakness (i.e., as-is situation, a gap or weakness that makes owner susceptible to something). It has the potential to increase the probability of a risk maturing or increasing the loss or impact of a maturing risk.

  • Reward. The positive outcome that may be acquired /achieved if a risk is taken. It makes taking the risk worthwhile and is typically the carrot that justifies taking the risk. The reward may or may not be guaranteed if the risk is taken. A risk jeopardizes the reward/benefit.

  • Mitigation Response. A response to a risk where actions are taken to reduce the impact of a risk.




Information Technology Security. Advice from Experts
Information Technology Security. Advice from Experts
ISBN: 1591402484
EAN: N/A
Year: 2004
Pages: 113

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net