Chapter 1
Measuring and Weighing Risk
THE FOLLOWING COMPTIA SECURITY+ EXAM OBJECTIVES ARE COVERED IN THIS CHAPTER:
2.1 Explain the importance of risk related concepts.
- Control types: Technical; Management; Operational
- False positives
- False negatives
- Importance of policies in reducing risk: privacy policy; acceptable use; security policy; mandatory vacations; job rotation; separation of duties; least privilege
- Risk calculation: likelihood; ALE; impact; SLE; ARO; MTTR; MTTF; MTBF
- Quantitative vs. qualitative
- Vulnerabilities
- Threat vectors
- Probability/threat likelihood
- Risk-avoidance, transference, acceptance, mitigation, and deterrence
- Risks associated ...
Get CompTIA Security+ Study Guide: SY0-401, 6th Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.