CRISC Certified in Risk and Information Systems Control flashcards
160 free flashcards. Tap a card to flip it.
Localized Policy Framework
Flip cardA governance approach for multinational organizations that integrates global corporate standards with specific local legal, regulatory, and cultural requirements to ensure compliance and consistency.
- Balances global consistency with local adaptability.
- Ensures adherence to diverse legal mandates.
- Mitigates country-specific compliance risks.
Memory trick: Think globally, act locally: blend the corporate cookbook with local ingredients.
Ethics by Design
Flip cardAn approach that embeds ethical considerations and principles into the entire lifecycle of technology development, from conception and design to implementation and operation, ensuring responsible innovation.
- Proactive ethical integration.
- Addresses societal, privacy, and bias concerns.
- Goes beyond mere compliance.
Memory trick: Design ethics into the AI, don't just patch it later.
Data Residency Compliance
Flip cardThe adherence to legal and regulatory requirements stipulating that certain data must be stored and processed within the geographical borders of a specific country or jurisdiction.
- Driven by national security, privacy, or economic policies.
- Often requires physical infrastructure within the country.
- A key consideration for global data architecture and cloud strategies.
Memory trick: When local laws demand data stays home, you build a local home for the data.
Risk Appetite Communication
Flip cardThe process of disseminating the board-approved risk appetite statement across the organization to guide decision-making at all levels.
- Ensures alignment of strategic goals with risk tolerance.
- Translates high-level strategy into actionable guidance.
- Fosters a unified risk culture.
Memory trick: Board's Appetite needs to be digested by everyone from top to bottom.
Legal, Regulatory, and Contractual Requirements
Flip cardObligations arising from laws, government regulations, and agreements that an organization must adhere to, impacting its risk posture.
- Vary significantly by industry and geography.
- Non-compliance can lead to fines, reputational damage, and legal action.
- Require continuous monitoring and adaptation.
Memory trick: Assess the laws before crossing borders.
Localized Governance Model
Flip cardA governance approach that establishes overarching global principles and standards while allowing for necessary adaptations to meet specific local legal, regulatory, and cultural requirements.
- Balances global consistency with local relevance.
- Ensures compliance across diverse jurisdictions.
- Supports operational efficiency and cultural acceptance.
Memory trick: Think 'Glocal' like a Global brand with Local flavors. Core recipe is same, but ingredients adapt.
Third-Party Risk Alignment
Flip cardThe process of ensuring that external vendors' and partners' risk management practices, policies, and controls align with an organization's own internal standards and risk appetite.
- Internal policies may exceed regulatory minimums.
- Negotiation is a key tool in third-party risk management.
- Proactive alignment reduces overall organizational risk.
Memory trick: Always align your partners' shields to your kingdom's standards.
Integrated Compliance
Flip cardThe practice of embedding legal and regulatory requirements directly into an organization's enterprise risk management (ERM) framework and operational processes.
- Ensures proactive identification and mitigation of compliance risks.
- Aligns compliance efforts with strategic business objectives.
- Reduces the likelihood of legal penalties and reputational damage.
Memory trick: Link Laws to Risks, Live Legit.
Resilience (System Design)
Flip cardThe ability of a system to withstand and recover from failures, disruptions, or attacks, while maintaining an acceptable level of service and functionality.
- Focuses on continuous operation despite issues.
- Involves redundancy, fault tolerance, and rapid recovery.
- Critical for high-availability systems.
Memory trick: Security is built-in, not bolted-on.
Preventive Control
Flip cardA security control designed to stop an undesirable event from occurring.
- Acts before an incident happens.
- Aims to reduce likelihood of risk.
- Examples include firewalls, access controls, encryption.
Memory trick: Prevent, Detect, Correct, Compensate.
Detective Control
Flip cardA security control designed to identify and alert to an incident after it has occurred or is in progress, allowing for a timely response.
- Identifies incidents
- Operates during or after an event
- Examples: IDS, security logs, audit trails
Memory trick: Prevent, Detect, Correct: The three phases of control.
Network Segmentation
Flip cardThe practice of dividing a computer network into smaller, isolated sub-networks or segments. This limits the lateral movement of threats and allows for more granular control over traffic.
- Enhances security by limiting attack spread.
- Commonly used for critical systems like ICS/SCADA.
- Can be achieved through VLANs, firewalls, or physical separation.
Memory trick: Divide and conquer, control access.
Attack Surface Management
Flip cardThe continuous process of discovering, classifying, prioritizing, and remediating vulnerabilities and potential entry points that an attacker could exploit to gain unauthorized access or disrupt systems.
- Aims to reduce the number of potential attack vectors.
- Involves identifying all accessible assets and their vulnerabilities.
- Proactive approach to security.
Memory trick: To 'Attack' fewer 'Surfaces', 'Trim' the 'Edges'.
Strategic Risk
Flip cardThe risk that an organization's strategy or its execution will prove to be flawed, leading to a failure to achieve objectives, often stemming from external factors or major business decisions.
- Associated with an organization's long-term goals.
- Includes market shifts, competitive landscape, regulatory changes.
- Can impact overall business viability and direction.
Memory trick: SOS, I'm 'Stuck' on a 'Strategic' mission!
Risk Treatment
Flip cardThe process of selecting and implementing measures to modify risk. It involves choosing one or more risk response strategies (e.g., mitigation, avoidance, sharing, acceptance) and putting them into action.
- Follows risk analysis and evaluation.
- Involves implementing controls or countermeasures.
- Aims to reduce risk likelihood or impact.
Memory trick: Establish, Assess, Treat, Monitor, Communicate.
Scope Management (Project Management)
Flip cardThe process of defining and controlling what is and is not included in the project. It ensures that the project team and stakeholders have a shared understanding of project deliverables and the work required to produce them.
- Defines project boundaries.
- Prevents scope creep.
- Crucial for successful project delivery.
Memory trick: Plan, Execute, Control: The project lifecycle.
Static Application Security Testing (SAST)
Flip cardA white-box testing method that analyzes application source code, bytecode, or binary code without executing it to identify security vulnerabilities.
- Performed early in the SDLC (e.g., during coding).
- Identifies vulnerabilities in the code itself.
- Does not require a running application.
Memory trick: SAST for code, DAST for run, PenTest for the whole shebang.
Cloud Portability
Flip cardThe ability to move applications and data from one cloud environment to another (or to on-premises) with minimal effort and re-engineering.
- Reduces vendor lock-in.
- Achieved through open standards, APIs, and containerization.
- Enhances flexibility and disaster recovery options.
Memory trick: To 'Move Clouds', 'Open Containers' are 'Key'.
HIPAA Security Rule
Flip cardA US federal law that establishes national standards to protect individuals' electronic protected health information (ePHI) that is created, received, used, or maintained by a covered entity.
- Mandatory for US healthcare entities.
- Focuses on administrative, physical, and technical safeguards.
- Ensures confidentiality, integrity, and availability of ePHI.
Memory trick: For 'Health' data, 'HIPAA' is the 'Hero'.
Risk Mitigation
Flip cardRisk mitigation involves implementing controls or actions to reduce the likelihood or impact of a risk event.
- Aims to decrease risk exposure.
- Can involve technical, administrative, or physical controls.
- Often a cost-benefit analysis is performed.
Memory trick: ARM-T: Avoid, Reduce, Mitigate, Transfer
NIST SP 800-53
Flip cardA publication by the National Institute of Standards and Technology (NIST) that provides a catalog of security and privacy controls for all U.S. federal information systems, but widely adopted globally.
- Comprehensive catalog of controls.
- Guidance for federal agencies, but applicable broadly.
- Supports risk management framework (RMF) implementation.
Memory trick: NIST for controls, ISO for the system, COBIT for governance, ITIL for service.
Shift Left (Security in SDLC)
Flip cardA practice that emphasizes integrating security activities and considerations earlier in the Software Development Life Cycle (SDLC) to identify and address vulnerabilities proactively, reducing costs and risks.
- Moves security from end to beginning of SDLC.
- Early detection is cheaper to fix.
- Includes threat modeling, secure coding, security testing.
Memory trick: Earlier is cheaper, safer, smarter.
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable duration of time following a disaster or disruption during which a business process or system can be unavailable without causing unacceptable consequences.
- Focuses on the 'time' aspect of recovery.
- Determined by business impact analysis (BIA).
- A key metric for disaster recovery planning.
Memory trick: RTO is 'Ready To Operate' time.
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data (measured in time) that an organization can afford to lose during a disaster or outage.
- Measures data loss in units of time (e.g., 1 hour, 24 hours).
- Determined by the business impact analysis (BIA).
- Influences backup and replication strategies.
Memory trick: RTO is about Time, RPO is about data Points.
Network Segmentation (IT/OT)
Flip cardDividing a computer network into smaller, isolated sub-networks to reduce the attack surface, limit lateral movement of threats, and protect critical systems like Operational Technology (OT).
- Crucial for converged IT/OT environments.
- Often involves firewalls, VLANs, and DMZs.
- Enhances security by containing breaches.
Memory trick: Separate 'IT' from 'OT' to 'Secure' the 'Factory'.
Shared Responsibility Model (IaaS)
Flip cardA framework outlining the security responsibilities between a cloud provider and a customer, where the customer is responsible for 'security in the cloud' and the provider for 'security of the cloud'.
- Customer manages OS, applications, data in IaaS.
- Provider manages physical infrastructure, virtualization.
- Responsibilities vary by cloud service model (IaaS, PaaS, SaaS).
Memory trick: Customer 'in' the cloud, Provider 'of' the cloud.
ISO/IEC 27001
Flip cardAn international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) within the context of the organization's overall business risks.
- Provides a risk-based approach.
- Technology-neutral and vendor-neutral.
- Certifiable standard, widely recognized globally.
Memory trick: Frameworks guide security, regulations enforce it.
Least Privilege
Flip cardA security principle that requires that a user or process be given only the minimum set of permissions necessary to perform its job or function.
- Reduces the attack surface and potential damage.
- Limits the impact of compromised accounts.
- Fundamental for strong access control.
Memory trick: For 'Critical' systems, 'Least Privilege' means 'Tiny Key'.
Administrative Control
Flip cardSecurity controls implemented through policies, procedures, guidelines, and training to manage human behavior and organizational processes related to security.
- Focuses on people and processes.
- Examples: security policies, awareness training, incident response plans.
- Often complements technical and physical controls.
Memory trick: Admin, Technical, Physical are the main control types.
Shift Left (DevSecOps)
Flip cardA principle in DevSecOps that emphasizes integrating security practices and testing into the earliest possible stages of the software development lifecycle (SDLC), rather than as an afterthought.
- Proactive security, not reactive.
- Aims to find and fix vulnerabilities early, reducing cost and effort.
- Often involves automated security testing in CI/CD.
Memory trick: Shift Left, Automate Everything, Culture of Security, Continuous Feedback.
Internal Audit (ISO 27001)
Flip cardA systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which the ISMS audit criteria are fulfilled.
- Mandatory requirement of ISO 27001 (Clause 9.2).
- Verifies ISMS conformity and effectiveness.
- Prepares the organization for external certification audits.
Memory trick: To 'Pass ISO', 'Internal Audit' is the 'Key Check'.
Risk Sharing
Flip cardA risk response strategy where the organization distributes the burden of a risk with another party, often through contracts, insurance, or partnerships.
- Involves collaboration with a third party.
- Distributes potential losses or impacts.
- Commonly achieved through insurance policies.
Memory trick: Always Share, Avoid, Mitigate, or Accept risks.
Containment (Incident Response)
Flip cardThe phase of incident response focused on limiting the scope and impact of a security incident by isolating affected systems and preventing further damage or spread.
- Immediate priority after detection and analysis.
- Aims to stop the bleeding.
- Can involve network segmentation, system shutdown, or service disabling.
Memory trick: Prep, Detect, Contain, Eradicate, Recover, Post-mortem.
Detection and Analysis (Incident Response)
Flip cardThe phase of incident response focused on identifying security events, determining if they are actual incidents, and analyzing their scope, nature, and impact.
- Involves monitoring systems and alerts.
- Aims for rapid identification of incidents.
- Includes initial assessment and categorization.
Memory trick: Plan, Detect, Contain, Eradicate, Recover, Post-mortem.
Annual Loss Expectancy (ALE)
Flip cardThe expected monetary loss that an organization can expect from a specific risk over a one-year period.
- Calculated using SLE and ARO.
- SLE (Single Loss Expectancy) = Asset Value (AV) * Exposure Factor (EF).
- ALE = SLE * ARO (Annualized Rate of Occurrence).
Memory trick: SLE is the single hit, ALE is the annual total.
Qualitative Risk Assessment
Flip cardA method of risk assessment that uses descriptive terms (e.g., low, medium, high) to evaluate the likelihood and impact of risks, rather than numerical values.
- Uses descriptive scales for likelihood and impact.
- Often presented in a risk matrix.
- Provides a quick, high-level overview of risks.
Memory trick: L-I-R: 'Likelihood', 'Impact', 'Rating' in a 'Grid'.
CSA Cloud Controls Matrix (CCM)
Flip cardA cybersecurity control framework from the Cloud Security Alliance (CSA) that lists security controls and compliance requirements specific to cloud computing, guiding cloud consumers and providers.
- Developed by the Cloud Security Alliance (CSA).
- Provides a common framework for cloud security controls.
- Maps to various other standards and regulations (e.g., ISO 27001, NIST, GDPR).
Memory trick: CSA CCM is the Cloud Control Master.
Maximum Tolerable Downtime (MTD)
Flip cardThe maximum period of time that a business process or function can be unavailable before the organization experiences unacceptable consequences.
- Determined during Business Impact Analysis (BIA).
- A business-driven metric.
- Higher than RTO, as RTO is a target for IT recovery, MTD is the business's absolute limit.
Memory trick: RPO, RTO, MTD: Time and data limits.
Residual Risk
Flip cardThe amount of risk that remains after all planned and implemented security controls have been put in place.
- Calculated as (Likelihood after controls) x (Impact after controls).
- Cannot be entirely eliminated.
- Must be accepted by management.
Memory trick: Risk = Likelihood times Impact, after controls it's residual.
Integrity (CIA Triad)
Flip cardThe assurance that information is accurate, complete, and protected from unauthorized modification or destruction.
- Prevents unauthorized alteration of data.
- Ensures data consistency and trustworthiness.
- Implemented through controls like hashing, access controls, versioning.
Memory trick: CIA: 'Confidentiality' (secret), 'Integrity' (true), 'Availability' (there).
Risk Transfer
Flip cardRisk transfer is a strategy where the financial or operational impact of a risk is shifted to another party, often through contracts or insurance.
- Does not eliminate the risk, only reassigns its burden.
- Commonly seen in insurance policies and service level agreements (SLAs).
- Requires clear contractual language.
Memory trick: Contractual clauses shift the burden, not the threat.
Cost-Benefit Analysis (CBA) in Risk Management
Flip cardA systematic process for calculating and comparing the benefits and costs of a project, decision, or proposed action (e.g., implementing a new security control).
- Evaluates economic feasibility of risk treatment.
- Compares cost of control vs. cost of risk.
- Helps justify security investments.
Memory trick: After fixing some, 'CBA' if more's 'Worth It'.
Integrate Risk Management
Flip cardA principle stating that risk management should be embedded into all organizational processes, decision-making, and structures, rather than being a separate or isolated activity.
- Risk considerations are part of daily operations.
- Not a 'bolt-on' activity.
- Ensures proactive risk treatment.
Memory trick: Risk is Integrated, Structured, Tailored, Inclusive, Dynamic, Best Available, Human, and Continually Improved.
Post-Incident Activity (Lessons Learned)
Flip cardThe final phase of the incident response lifecycle, focused on reviewing the incident, identifying root causes, documenting lessons learned, and implementing changes to prevent recurrence and improve future response.
- Occurs after recovery.
- Aims for continuous improvement.
- Involves root cause analysis and policy updates.
Memory trick: Plan, Spot, Stop, Fix, Learn.
Return on Investment (ROI) for Security
Flip cardA financial metric used to evaluate the efficiency of a security investment by comparing the monetary benefit (reduced losses) to the cost of the investment.
- Calculated as (Savings - Cost) / Cost.
- Savings typically derived from reduced Annual Loss Expectancy (ALE).
- Helps justify security expenditures to management.
Memory trick: Savings minus Cost, then divide by Cost.
Risk Register Completeness
Flip cardA complete risk register includes detailed information for each risk, such as description, impact, likelihood, existing controls, control effectiveness, and residual risk.
- Facilitates informed decision-making.
- Provides a current view of the risk landscape.
- Essential for monitoring and reporting.
Memory trick: A register is complete when it 'Covers All Controls and Residuals'.
Qualitative Risk Scale Consistency
Flip cardEnsuring that subjective risk ratings (e.g., 'High', 'Medium', 'Low') are applied uniformly and objectively by different assessors through clear, explicit definitions and criteria.
- Reduces subjectivity in risk assessment.
- Requires detailed definitions for likelihood and impact levels.
- Enhances comparability and reliability of risk ratings.
Memory trick: To be 'Consistent,' define 'Clearly' what each 'Level' means.
Fault Tree Analysis (FTA)
Flip cardA top-down, deductive failure analysis method in which an undesired state of a system is analyzed using Boolean logic to combine a series of lower-level events.
- Identifies root causes of system failures.
- Uses graphical representation (tree structure).
- Helps quantify probability of system failure.
Memory trick: Risk ID: Find the Fails, Brainstorm the Bumps, Delphi the Decisions, Walk the Work.
ARO Estimation Challenges
Flip cardDifficulties in accurately determining the Annualized Rate of Occurrence due to lack of historical data, unique environments, or emerging threats.
- Common in quantitative risk analysis.
- Requires alternative methods when direct data is unavailable.
- Expert judgment and industry data are key alternatives.
Memory trick: When the ARO data is a mystery, consult the wise and look at the neighbors.
Residual Risk Acceptance
Flip cardThe formal acknowledgement and agreement by management to tolerate the remaining risk after all mitigation and control activities have been implemented.
- Occurs when risk cannot be fully eliminated or treated economically.
- Requires informed decision-making by appropriate authority.
- Should be formally documented.
Memory trick: After treating, what's left must be 'Accepted' or 'Addressed More'.
Risk Scenario Detail
Flip cardA well-defined risk scenario clearly describes the threat, the vulnerability, the asset at risk, the event that could occur, and the potential impact.
- Answers 'what can happen?', 'how?', and 'what are the consequences?'.
- Makes risks actionable and measurable.
- Avoids vague or generic descriptions.
Memory trick: A good scenario is a STORY: Source, Threat, Event, Impact.
Risk Identification Techniques
Flip cardMethods used to discover, recognize, and describe risks that could affect an organization's objectives.
- Aims to be comprehensive and systematic.
- Combines historical analysis with forward-looking approaches.
- Involves various stakeholders and perspectives.
Memory trick: Identify ALL risks, known and unknown, like a detective with a magnifying glass.
Risk Register Elements
Flip cardA central repository for all identified risks, their analysis, and response plans.
- Includes risk ID, description, owner, likelihood, impact, and response.
- Supports ongoing monitoring and review.
- Facilitates communication about risks.
Memory trick: The Register has IDs, Descriptions, Owners, and Plans.
Vendor Lock-in Risk
Flip cardThe risk that an organization becomes dependent on a single vendor for products or services and cannot easily switch to another vendor without substantial costs, effort, or business disruption.
- Prevalent in cloud computing and proprietary technologies.
- Impact is typically measured by exit costs and migration complexity.
- Can limit flexibility and increase long-term costs.
Memory trick: Lock-in means your wallet is tied to one vendor.
Threat Modeling
Flip cardA structured approach to identify potential threats, vulnerabilities, and attacks against a system or application during its design or development phase.
- Focuses on system architecture and data flow.
- Proactive rather than reactive.
- Helps prioritize security efforts.
Memory trick: Imagine a detective modeling a crime scene to find all the possible threats.
Actionable Risk Scenarios
Flip cardRisk scenarios that are detailed enough to inform specific risk treatment plans and guide decision-making for risk response.
- Go beyond mere identification of threat and impact.
- Include triggers, vulnerabilities, and potential response options.
- Facilitate practical planning and resource allocation.
Memory trick: An actionable scenario isn't just a story; it's a 'choose your own adventure' with solutions.
Risk Response Strategies
Flip cardActions taken to address identified risks, typically categorized as avoid, accept, mitigate, or transfer.
- Aims to bring risk levels within the organization's risk appetite.
- Chosen strategy depends on risk level, cost, and feasibility.
- Often involves a combination of strategies.
Memory trick: AART: Avoid, Accept, Reduce (Mitigate), Transfer.
Risk Scenario Components
Flip cardKey elements that define a risk scenario, typically including threat, vulnerability, asset, and impact.
- Threat: The potential cause of an incident.
- Vulnerability: A weakness that can be exploited by a threat.
- Asset: Something of value that needs protection.
Memory trick: TVA-I: Threats Vandalize Assets, causing Impact.
FAIR Ontology
Flip cardA framework for understanding, analyzing, and measuring information risk in financial terms, by breaking down risk into quantifiable factors.
- Focuses on quantitative risk analysis.
- Decomposes risk into standard factors (e.g., Loss Event Frequency, Probable Loss Magnitude).
- Aims to provide objective, defensible risk measurements.
Memory trick: FAIR breaks risk down like a scientist, then puts a price tag on it.
Risk Register Optimization
Flip cardThe process of refining and maintaining a risk register to ensure it is accurate, relevant, actionable, and effectively supports risk management decision-making.
- Involves cleaning up outdated or duplicate entries.
- Focuses on specificity and clarity of risk descriptions.
- Ensures alignment with organizational risk appetite.
Memory trick: First, 'Clean' the register, then 'Organize' and 'Utilize' it.