§ — — Information Assurance and Security 2
Organizations rely on policies and standards to guide security practices. Examples include ISO/IEC 27001 (an international information security management standard) and the NIST Cybersecurity Framework. A security policy defines roles and responsibilities (for example, an Acceptable Use Policy or Incident Response Policy). Auditors check that organizations follow these standards. For instance, a Philippine company might align with ISO 27001 and the National Privacy Commission's policies to ensure comprehensive coverage of security and privacy requirements.
Risk management involves identifying, analyzing, and mitigating risks. Techniques include qualitative analysis (using risk matrices to rate impact and likelihood) and quantitative analysis (calculating expected losses). A key formula is Single Loss Expectancy (SLE) = Asset Value × Exposure Factor and Annual Loss Expectancy (ALE) = SLE × Annualized Rate of Occurrence (ARO). Controls (like firewalls or encryption) reduce risk by lowering either the likelihood or the impact. A key step is performing risk assessments: listing assets, threats, vulnerabilities, and determining the level of risk. Exams often ask you to perform or interpret simple risk calculations using these formulas.
ProReviewer — locked
Drills, code labs, and full solutions.
ProReviewer — locked
Drills, code labs, and full solutions.
ProReviewer — locked
Drills, code labs, and full solutions.
Done with this module? Track it — your progress shows on the subject list.
You've finished this subject