CSS Threat Intelligence and Risk Communication Flashcards
6 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CSS Threat Intelligence and Risk Communication flashcards as text
Which risk communication framework is most useful when helping a client prioritize which security gaps to address first?
Answer: A risk matrix that plots likelihood of occurrence against severity of impact
A risk matrix allows both the CSS and the client to visualize which threats require immediate action based on probability and potential impact, enabling prioritized investment.
A CSS should update threat intelligence presentations for existing clients primarily because:
Answer: The threat environment evolves continuously, and clients' risk exposures change over time
The threat landscape shifts as criminal methods evolve, new vulnerabilities emerge, and clients' businesses change, requiring updated risk communications to remain relevant.
When a CSS references an ASIS International guideline in a client presentation, it serves to:
Answer: Demonstrate that your recommendations align with recognized professional security standards
Citing ASIS guidelines shows that your security recommendations are grounded in standards developed by the leading professional organization in physical security.
Which term describes the process of quantifying potential financial losses from security incidents to justify a proposed security investment?
Answer: Annual loss expectancy (ALE) analysis
Annual loss expectancy combines the frequency and financial impact of potential incidents to produce a dollar figure that can be compared directly to the cost of security controls.
A CSS presenting to a financial institution about tailored security risks should most prominently feature:
Answer: Robbery patterns, ATM attacks, data room physical security, and bank-specific regulatory security requirements
Effective threat intelligence is sector-specific; financial institutions face distinct threats including robbery, ATM skimming, vault security, and physical safeguard compliance unique to their industry.
The 'consequence' dimension of a risk assessment in physical security refers to:
Answer: The magnitude of harm or loss that would result if a specific threat were successfully carried out
Consequence measures the severity of outcomes — financial loss, injury, reputational damage — if a threat event successfully occurs, which drives prioritization alongside likelihood.