From the course: CCSP Cert Prep: 6 Legal, Risk, and Compliance Audio Review

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Risk assessment

Risk assessment

From the course: CCSP Cert Prep: 6 Legal, Risk, and Compliance Audio Review

Start my 1-month free trial

Risk assessment

- [Instructor] In chapter one, I covered risk assessment. Everything we do as cybersecurity professionals is focused on managing risk, and this is definitely true in the cloud. To discuss risk, we need to have some basic terminology down. First, a threat is any external force that jeopardizes security. This could be a naturally occurring event such as a hurricane or a human adversary such as a hacker. A vulnerability is a weakness in our own environment that exposes us to a threat. This might be a poorly written firewall rule, a missing patch, or something else that presents an opening for an attack. And then a risk is the combination of a threat and a corresponding vulnerability. We need both of those elements, a threat and a vulnerability, to have a risk. When we encounter risks, we evaluate them based upon two critical factors. First, the likelihood that they will occur and then second, the impact on our business…

Contents