From the course: ISACA Certified Information System Manager (CISM) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Risk assessment and analysis
From the course: ISACA Certified Information System Manager (CISM) Cert Prep
Risk assessment and analysis
- [Instructor] And risk assessment is all about figuring out a value for the risk. What do we stand to lose? Because I can't appropriately choose a mitigation strategy until I understand the value of the risk. So, in risk assessment, we can look at both qualitative and quantitative analysis. Both of them are concerned with getting a value. It's just that a qualitative analysis is more subjective in nature, and a quantitative analysis is more fact-based, more objective. Again, now we're focused on value. Now, that value can come in two different flavors. Qualitative analysis. This is usually our starting point. And you're doing qualitative analysis when you're using words like low, medium, high. How much of a chance is there it's going to rain this weekend? There's medium chance. That's a qualitative analysis. And the thing about a qualitative analysis is it doesn't require research. It really is more based on gut feeling, it's based on experience, which is one of the reasons that it's…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
Risk definitions21m 39s
-
(Locked)
Bias5m 31s
-
(Locked)
Developing a risk management program6m 3s
-
(Locked)
NIST 800-397m 12s
-
(Locked)
NIST 800-306m 12s
-
(Locked)
Risk management lifecycle2m 4s
-
(Locked)
Risk assessment and analysis10m 50s
-
(Locked)
NIST SP 800-37 Rev. 1 and SDLC8m 5s
-
(Locked)
Risk response6m 10s
-
(Locked)
Risk action plan7m 5s
-
Risk acceptance9m 12s
-
(Locked)
Risk mitigation4m 29s
-
(Locked)
Risk avoidance, sharing, and transfer9m 37s
-
(Locked)
Risk scenarios7m 39s
-
(Locked)
Risk register6m 15s
-
(Locked)
Cost-benefit analysis and ROI12m 15s
-
(Locked)
Risk monitoring and communications16m 7s
-
(Locked)
Risk governance and management4m 48s
-
(Locked)
Risk review5m 36s
-
-
-
-