9 Security Risk Management

Information Security · Unit 9

Security Risk Management

Exam-focused notes for Security Risk Management (Information Security, BIT303): what the TU syllabus asks and how it has actually been tested, with 3 solved past questions from this unit.

What this unit covers

  • Risk definition and analysis
  • Security risk assessment aspects
  • Risk treatment methods
  • Logging function implementation

Risk treatment methods

20815 marks

Discuss various methods of risk treatment during security risk analysis. [5]

Risk treatment refers to the process of selecting and implementing measures to modify risk. After risks have been identified and assessed, an organization must decide how to handle each risk. There are four main methods of risk treatment: --- - Definition: ...

Full solved answer →

Security risk assessment aspects

20795 marks

What is security risk assessment? What are different aspects of a successful security risk assessment? [5]

Security Risk Assessment is a systematic process of identifying, analyzing, and evaluating potential security threats and vulnerabilities within an information system or organization. It helps determine the likelihood and impact of security incidents and gu...

Full solved answer →

Risk definition and analysis

05 marks

What is risk? How security risk analysis is done? [5]

Risk is the potential for loss or damage when a threat exploits a vulnerability in a system or asset. It represents the likelihood that a harmful event will occur and the impact it will have on an organization's assets, operations, or information. Risk = Th...

Full solved answer →