Risk Management & Security Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Security flashcards as text
Which type of risk assessment methodology assigns numeric values to the likelihood and impact of threats to calculate an overall risk score?
Answer: Quantitative assessment
Quantitative risk assessment uses numeric values and formulas (such as ALE = ARO × SLE) to produce measurable risk scores.
A records manager discovers that classified contracts are stored in an unlocked filing cabinet in a shared workspace. This situation primarily represents which category of risk?
Answer: Operational risk
Operational risk arises from failures in internal processes, people, or physical controls, such as inadequate physical security for records.
Under NIST SP 800-60, what is the primary purpose of information type categorization?
Answer: To determine the appropriate security category for federal information systems
NIST SP 800-60 maps information types to security categories (confidentiality, integrity, availability) to guide federal information system security.
Which control is specifically designed to limit the number of employees who can access highly sensitive personnel records?
Answer: Need-to-know access
Need-to-know access restricts record access to only those individuals whose job functions require it, reducing unauthorized disclosure risk.
A records security plan should address which of the following to protect records during a declared disaster?
Answer: Vital records protection and off-site storage
Vital records protection, including duplication and off-site storage, ensures critical records survive disasters and support business continuity.
What is the recommended first step when an organization suspects a records-related data breach?
Answer: Contain the breach and assess the scope before further action
Incident response best practice requires containment and assessment of the breach scope before notifications or other remedial actions.
Which document formally authorizes an organization's information security program and assigns high-level accountability to senior management?
Answer: Information security policy
An information security policy is a high-level management directive that establishes the program, assigns responsibility, and sets the tone for compliance.