CRISC Certified in Risk and Information Systems Control flashcards
160 free flashcards. Tap a card to flip it.
Qualitative Risk Scale Consistency
Flip cardEnsuring that subjective risk ratings (e.g., 'High', 'Medium', 'Low') are applied uniformly and objectively by different assessors through clear, explicit definitions and criteria.
- Reduces subjectivity in risk assessment.
- Requires detailed definitions for likelihood and impact levels.
- Enhances comparability and reliability of risk ratings.
Memory trick: To be 'Consistent,' define 'Clearly' what each 'Level' means.
Risk Register Completeness
Flip cardA complete risk register includes detailed information for each risk, such as description, impact, likelihood, existing controls, control effectiveness, and residual risk.
- Facilitates informed decision-making.
- Provides a current view of the risk landscape.
- Essential for monitoring and reporting.
Memory trick: A register is complete when it 'Covers All Controls and Residuals'.
Annualized Loss Expectancy (ALE)
Flip cardThe estimated financial loss from a specific risk over a one-year period.
- Calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO).
- Used in quantitative risk analysis.
- Helps prioritize risks based on financial impact.
Memory trick: ALE: Annual Loss Expected, calculated by SLE and ARO.
Risk Appetite Threshold
Flip cardThe level of risk that an organization is willing to accept in pursuit of its objectives, often expressed as a limit or range for specific risk metrics.
- Defines acceptable and unacceptable risk levels.
- Guides risk treatment decisions.
- Should be formally approved by senior management.
Memory trick: If risk is 'Unacceptable', 'Act' to 'Reduce' it, don't just 'Accept'.
Qualitative Risk Matrix
Flip cardA tool used in risk analysis to plot the likelihood of a risk occurrence against its potential impact, resulting in a qualitative risk level (e.g., Low, Medium, High).
- Simplifies complex risk data for decision-making.
- Uses descriptive terms rather than numerical values for likelihood and impact.
- Provides a visual representation of risk prioritization.
Memory trick: Matrix crossroads: likelihood meets impact, and a risk level is born.
FAIR Components
Flip cardA quantitative risk analysis model that defines, measures, and analyzes information risk.
- Focuses on Loss Event Frequency and Loss Magnitude.
- Breaks down risk into measurable factors.
- Provides a common language for risk quantification.
Memory trick: FAIR: Frequency And Impact Really (matter).
Defense in Depth
Flip cardA strategy that employs multiple layers of security controls to protect against a single point of failure.
- Uses a combination of administrative, technical, and physical controls.
- Aims to slow down an attacker or prevent a breach if one layer fails.
- Enhances overall resilience and robustness of security posture.
Memory trick: Design Controls Diligently for Defense.
Detective Controls
Flip cardControls designed to identify and alert about undesirable events that have already occurred.
- Act after an event has taken place.
- Aim to discover errors or irregularities.
- Examples: audit trails, intrusion detection systems, reconciliation.
Memory trick: PDC: Prevent, Detect, Correct.
Residual Risk Response
Flip cardActions taken when the remaining risk after implementing controls (residual risk) is deemed too high, requiring further treatment.
- Involves re-assessing and re-treating risk
- May lead to new controls or different strategies
- Aims to bring risk within acceptable appetite
Memory trick: Rethink, Re-plan, Respond – Don't just sit there!
Separation of Duties (Control Design)
Flip cardA control principle that divides critical functions among multiple individuals or teams to prevent a single person from controlling an entire process and to reduce the risk of fraud or error.
- Prevents conflict of interest
- Requires multiple parties for critical tasks
- Reduces insider threat and error
Memory trick: Secure Design: Think SOL-D (Separation, Open, Least, Defense)
Risk Likelihood Reduction
Flip cardA risk response strategy focused on implementing controls and measures to decrease the probability or frequency of a specific risk event occurring.
- Aims to prevent the risk from materializing.
- Involves proactive controls and process improvements.
- Examples include training, redundancy, and robust testing.
Memory trick: Likelihood is Lowered by Proactive Prevention.
Shift-Left Security
Flip cardShift-left security is a practice that integrates security processes, tools, and testing into the earliest phases of the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Moves security from end-of-cycle to beginning.
- Aims to find and fix bugs cheaper and faster.
- Often involves automated testing in CI/CD pipelines.
Memory trick: Shift Left: Secure it early, save it later.
Control Effectiveness Assessment
Flip cardThe process of evaluating whether controls are suitably designed and operating as intended to achieve their objectives and mitigate risks to acceptable levels.
- Assesses both design effectiveness and operational effectiveness.
- Controls can be fully effective, partially effective, or ineffective.
- Critical for determining residual risk.
- Requires regular monitoring and testing.
Memory trick: Effectiveness is a Spectrum, Not a Simple Switch.
Control Objective: Confidentiality
Flip cardProtecting sensitive information from unauthorized access and disclosure to unauthorized individuals or systems.
- Prevents data breaches and leaks.
- Achieved through encryption, access controls, data masking.
- Critical for privacy and competitive advantage.
Memory trick: CIA+N: Confidentiality, Integrity, Availability, Non-repudiation.
Risk Sharing (Transfer)
Flip cardA risk response strategy where the burden or responsibility for a risk, or its consequences, is shared with or shifted to another party, often through contracts, partnerships, or insurance.
- Involves another entity
- Distributes risk responsibility
- Does not eliminate the risk entirely
Memory trick: SHARE the load, don't carry it all!
Control Effectiveness (Accuracy)
Flip cardThe degree to which a control achieves its intended objective, often measured by its ability to prevent, detect, or correct risks accurately and consistently.
- Involves precision (reducing false positives)
- Involves recall (not missing true positives)
- Impacts the reliability of risk reporting
Memory trick: Accuracy is Key: True P's, False N's, no noise!
Risk Owner
Flip cardA risk owner is the individual or entity with the accountability and authority to manage a particular risk, including its identification, assessment, response, and monitoring.
- Accountable for specific risks.
- Has authority to make risk treatment decisions.
- Ensures risks are managed throughout their lifecycle.
Memory trick: The 'O' in Owner means 'Overall' responsibility.
Risk and Control Ownership
Flip cardThe clear assignment of responsibility and accountability for managing specific risks and ensuring the effective operation of controls to individuals or entities within an organization.
- Crucial for effective governance and risk management.
- Ensures risks are actively monitored and controls are maintained.
- Lack of clear ownership can lead to control gaps and unmanaged risks.
Memory trick: No owner, no care, data's flawed, financial despair.
Control Design Effectiveness
Flip cardThe degree to which a control, if operating as prescribed, is capable of preventing or detecting a material misstatement or breakdown in achieving a control objective.
- Focuses on the structure and logic of the control.
- Evaluates if the control is properly conceived.
- Distinguishes from operational effectiveness (how it actually works).
Memory trick: Design, Implement, Monitor, Document (DIMD) for effective controls.
Control Objectives (Confidentiality)
Flip cardSpecific goals or statements that describe the desired outcome of implementing controls, such as protecting data from unauthorized disclosure.
- Often linked to CIA triad (Confidentiality, Integrity, Availability)
- Guides control design and implementation
- Helps measure control effectiveness
Memory trick: CIA: Confidentiality, Integrity, Availability – a secret agent's job!
Preventive Controls
Flip cardControls designed to stop undesirable events from happening in the first place, thereby reducing the likelihood of a risk event occurring.
- Aimed at preventing errors, omissions, or malicious acts.
- Operate before a risk event can materialize.
- Examples include access controls, encryption, and training.
Memory trick: Prevent Before, Detect During, Correct After.
Integrated Risk Management (IRM)
Flip cardA holistic approach that aims to unify and coordinate all risk management activities across an organization, ensuring a consistent view and response to risks.
- Breaks down risk silos
- Provides a comprehensive view of risk
- Aligns risk management with business objectives
Memory trick: ERM: Everyone's Risk Management – Unified!
Effective Risk Reporting Characteristics
Flip cardEffective risk reporting provides relevant, accurate, timely, consistent, and clear information to stakeholders, enabling informed decision-making regarding risk management.
- Must be consistent across departments/time.
- Should be tailored to the audience.
- Enables holistic risk understanding.
Memory trick: TACC-C: Timely, Accurate, Complete, Clear, Consistent.
Control Monitoring Optimization
Flip cardThe process of refining and improving the effectiveness and efficiency of controls that track and evaluate security performance.
- Aims to enhance detection capabilities.
- Often involves technology and process improvements.
- Focuses on efficiency and relevance of alerts.
Memory trick: SIEM: See, Identify, Evaluate, Monitor
Risk Transfer (Financial)
Flip cardRisk transfer, in a financial context, involves shifting the financial consequences of a potential risk event to another party, often through contracts, insurance policies, or indemnification clauses.
- Shifts financial burden, not necessarily the risk itself.
- Commonly achieved via insurance or contractual agreements.
- Does not eliminate the risk, but reallocates its financial impact.
Memory trick: Transfer the pain, but not the blame.
Control Effectiveness
Flip cardThe degree to which a control achieves its intended security objective.
- Measured by whether the control mitigates the identified risk.
- Often assessed through testing, monitoring, and audit reviews.
- A crucial metric for ongoing risk management.
Memory trick: Monitor Exactly For Effective Results.
Risk Mitigation with Residual Acceptance
Flip cardA combined risk response strategy where active measures are taken to reduce a risk's likelihood or impact (mitigation), and any remaining risk after these measures are applied is formally acknowledged and accepted by management.
- Involves actively reducing risk through controls.
- Acknowledges that some risk will always remain.
- Formal acceptance of residual risk is a critical governance step.
- Common when risks cannot be fully eliminated or transferred.
Memory trick: Mitigate What You Can, Accept What Remains, Document It All.
Control Objective: Integrity
Flip cardEnsuring the accuracy, completeness, and validity of data and information, and protecting it from unauthorized modification.
- Data remains unaltered and correct.
- Prevents unauthorized changes.
- Supports auditability and trustworthiness.
Memory trick: CIA+N: Confidentiality, Integrity, Availability, Non-repudiation.
Compensating Control
Flip cardAn alternative control that is implemented to mitigate risk when a primary control is not feasible, effective, or available.
- Addresses a control deficiency
- Provides an equivalent level of protection
- Often more complex or costly than primary controls
Memory trick: When the main path is broken, use a COMPENSATING detour!
Residual Risk Trend
Flip cardThe observed pattern or direction of residual risk levels over a period, indicating the effectiveness of risk management efforts.
- Calculated after all controls are applied.
- A key indicator of risk program performance.
- Used to inform strategic decisions and resource allocation.
Memory trick: Report Residual Trends For Success.
Third-Party Risk Monitoring
Flip cardThe ongoing process of assessing and evaluating the risks introduced by external vendors, partners, or service providers.
- Involves continuous oversight
- Uses various assurance methods (e.g., audits, certifications)
- Aims to ensure third-party controls meet organizational requirements
Memory trick: Third-Party Trust: Verify, Don't just rely!
Third-Party Risk Management
Flip cardThe process of identifying, assessing, and controlling risks associated with external entities that provide services or products to an organization.
- Requires due diligence before engagement.
- Contractual agreements are key for defining responsibilities.
- Ongoing monitoring of third-party performance is essential.
Memory trick: Contracts Clarify Commitments and Compliance.
Control Monitoring Breakdown
Flip cardA failure in the ongoing processes designed to assess the presence, effectiveness, and continued operation of controls over time, leading to control deficiencies.
- Controls may be designed well but fail in execution or maintenance.
- Includes lack of regular reviews, audits, or checks.
- Can lead to controls becoming ineffective or outdated.
- Highlights the importance of continuous assurance activities.
Memory trick: Monitoring's Missing, Controls are Crumbling, Risks are Rising.
Control Monitoring Effectiveness
Flip cardControl monitoring effectiveness assesses how well the processes in place detect control failures, deviations, or risk events, and ensure that appropriate actions are taken based on the monitoring results.
- Focuses on the ongoing review and analysis of control performance.
- Includes processes for identifying and addressing control deficiencies.
- Crucial for ensuring controls remain effective over time.
Memory trick: Monitor and React: Don't just watch, act!
Control Effectiveness vs. Underlying Risk
Flip cardDistinguishing between a control's operational effectiveness in stopping an event and the continued presence of the underlying risk or behavior that necessitates the control.
- A control can be effective in preventing an event, but the attempts may indicate a persistent underlying issue (e.g., user error, malicious intent).
- Effective controls reduce residual risk, but do not eliminate the inherent risk.
- Monitoring control output (e.g., blocked attempts) can provide insights into risk trends and control gaps.
- Addressing underlying causes (e.g., training, process improvement) is crucial even with effective controls.
Memory trick: Blocked Attempts Mean Control is Working, But What's Causing the Warning?
Risk Mitigation (Impact Reduction)
Flip cardRisk mitigation, specifically focused on impact reduction, involves implementing measures to lessen the severity of consequences if a risk event occurs.
- Aims to reduce the severity of loss or disruption.
- Often involves redundancy, disaster recovery, or business continuity planning.
- Distinguished from likelihood reduction, which prevents the event.
Memory trick: Mitigate by Making the hit less hard.
Third-Party Assurance Review
Flip cardThe process of evaluating the effectiveness of controls implemented by an external service provider.
- Crucial for managing supply chain risk.
- Often involves reviewing SOC reports, certifications, and security policies.
- Ensures third parties align with organizational risk appetite and requirements.
Memory trick: Monitoring external parties needs assurance.
Risk Mitigation with Acceptance
Flip cardA strategy where controls are implemented to reduce a risk, and any remaining (residual) risk is consciously acknowledged and accepted.
- Most risks cannot be fully eliminated.
- After mitigation, organizations often accept the residual risk.
- Requires a clear understanding of the remaining risk exposure.
Memory trick: Mitigate what you can, accept what's left.
Control Documentation Purpose
Flip cardThe primary role of control documentation is to provide a clear, detailed record of controls for effective monitoring, maintenance, and assurance.
- Essential for understanding how controls are designed and operate.
- Facilitates control monitoring and testing.
- Supports compliance, audits, and continuous improvement.
Memory trick: Document controls to KEEP them working.
Confidentiality
Flip cardThe control objective that ensures information is not disclosed to unauthorized individuals or systems.
- A fundamental principle of information security (CIA triad).
- Achieved through access controls, encryption, and data classification.
- Aims to prevent unauthorized viewing or access of sensitive data.
Memory trick: Confidentiality: Keep secrets safe.