From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 25,500 courses taught by industry experts.

Risk assessment and management

Risk assessment and management

- To begin this lesson on risk management activities, let's define overall risk assessment and management. This is the consistent process of identifying, analyzing, evaluating, and treating loss exposures while observing risk control and resources to mitigate adverse effects. It's a practice employed within IT departments, basically to mitigate potential cyber threats to start with. But of course we have other threats besides just cyber threats. So there's five elements of risk analysis, probably something that you learned at the security plus level. But let's just remind ourselves here, the five elements of risk. We have an asset or an asset class. For example, your web servers in your intranet, right? Or your email system. It could be a certain scenario, right? A certain type of attack, let's say a ransomware attack or something that's trying to be put on your CEO's laptop. Then you have likelihood or probability and then impact or magnitude. And then finally, you do the analysis…

Contents