To identify and classify risk, it is necessary to examine all activities and relationships of a facility and develop answers to which of the following three basic considerations?
To identify and classify risk effectively, a security practitioner must understand:
Assets: What needs protection.
Exposure: What threats or vulnerabilities exist.
Losses: What the impact would be if threats materialize.
This foundational analysis guides the prioritization and mitigation of risk.
B, C, and D mix relevant terms but do not define the core framework for risk identification.
[References:, PSP Study Guide – Risk Assessment Methodologies, POA Manual – Risk and Vulnerability Analysis]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit